FW-IDS-iptables-Flowchart-v2024-05-22

2 comments

  1. I’ve got packets entering via the lan interface which need to go out the wan interface. Works fine with NAT off, when I put NAT on it’s more difficult. such packets don’t seem to be covered in your flowchart.

    1. Those would be handled by this path:
      raw:PREROUTING –> mangle:PREROUTING –> nat:PREROUTING –> mangle:FORWARD –> filter:FORWARD –> security:FORWARD –> mangle:POSTROUTING –> nat:POSTROUTING.

Leave a comment

Your email address will not be published. Required fields are marked *