2006-7-14 11:45
lc1999
问一个关于iptables防火墙的概念问题?
The INPUT chain is for packets addressed to your machine.
The OUTPUT chain is for packets from your machine.
The FORWARD chain is for packets that aren't to or from your machine - that
you'd have to forward.
上面讲:对一个包,如果其目的是"你的机器", 那就是input的包,用input链处理.
这里,"你的机器"是指防火墙服务器本身吗?还是指内部网的某台机器?
我觉得是防火墙本身.
不过,这样的话,防火墙的两个网卡是不是都要对每一个接受到的包进行判断呢?
的确有点迷糊.
谢谢!