zoukankan      html  css  js  c++  java
  • Linux Kernel Packet Traveling

                               Network
                        -----------+-----------
                                   |
                      +--------------------------+
              +-------+-------+        +---------+---------+
              |    IPCHAINS   |        |      IPTABLES     |
              |     INPUT     |        |     PREROUTING    |
              +-------+-------+        | +-------+-------+ |
                      |                | |   conntrack   | |
                      |                | +-------+-------+ |
                      |                | |    mangle     | | <- MARK WRITE  
                      |                | +-------+-------+ |
                      |                | |      IMQ      | |
                      |                | +-------+-------+ |
                      |                | |      nat      | | <- DEST REWRITE
                      |                | +-------+-------+ |     DNAT or REDIRECT or DE-MASQUERADE
                      |                +---------+---------+
                      +------------+-------------+
                                   |
                           +-------+-------+
                           |      QOS      |
                           |    INGRESS    |
                           +-------+-------+
                                   |
             packet is for +-------+-------+ packet is for
              this machine |     INPUT     | another address
            +--------------+    ROUTING    +--------------+
            |              |    + PDBB     |              |
            |              +---------------+              |
    +-------+-------+                                     |
    |   IPTABLES    |                                     |
    |     INPUT     |                                     |
    | +-----+-----+ |                                     |
    | |   mangle  | |                                     |
    | +-----+-----+ |                                     |
    | |   filter  | |                                     |
    | +-----+-----+ |                                     |
    +-------+-------+                                     |
            |                               +---------------------------+
    +-------+-------+                       |                           |
    |     Local     |               +-------+-------+           +-------+-------+
    |    Process    |               |    IPCHAINS   |           |    IPTABLES   |
    +-------+-------+               |    FORWARD    |           |    FORWARD    |
            |                       +-------+-------+           | +-----+-----+ |
    +-------+-------+                       |                   | |  mangle   | | <- MARK WRITE
    |    OUTPUT     |                       |                   | +-----+-----+ |
    |    ROUTING    |                       |                   | |  filter   | |
    +-------+-------+                       |                   | +-----+-----+ |
            |                               |                   +-------+-------+
    +-------+-------+                       |                           |
    |    IPTABLES   |                       +---------------------------+
    |     OUTPUT    |                                     |
    | +-----------+ |                                     |
    | | conntrack | |                                     |
    | +-----+-----+ |                                     |
    | |   mangle  | | <- MARK WRITE                       |
    | +-----+-----+ |                                     |
    | |    nat    | | <-DEST REWRITE                      |
    | +-----+-----+ |     DNAT or REDIRECT                |
    | |   filter  | |                                     |
    | +-----+-----+ |                                     |
    +-------+-------+                                     |
            |                                             |
            +----------------------+----------------------+
                                   |
                      +------------+------------+
                      |                         |
              +-------+-------+       +---------+---------+
              |    IPCHAINS   |       |      IPTABLES     |
              |     OUTPUT    |       |    POSTROUTING    |
              +-------+-------        | +-------+-------+ |
                      |               | |    mangle     | | <- MARK WRITE  
                      |               | +-------+-------+ |
                      |               | |      nat      | | <- SOURCE REWRITE
                      |               | +-------+-------+ |      SNAT or MASQUERADE
                      |               | |      IMQ      | |
                      |               | +-------+-------+ |
                      |               +---------+---------+
                      +------------+------------+
                                   |
                            +------+------+
                            |     QOS     |
                            |    EGRESS   |
                            +------+------+
                                   |
                        -----------+-----------
                                Network
  • 相关阅读:
    FAL_CLIENT和FAL_SERVER参数详解
    Goldengate OGG常见问题与错误列表
    Goldengate:ERROR 180 encountered commit SCN that is not greater than the highest SCN already processed
    OGG-01028 Incompatible Record解决办法
    goldengate–使用filter+@GETENV在线重新初始化指定的table
    RAC环境中threads变更后如何确保goldengate继续正常复制
    default listener is not configured in grid infrastructure home
    11gr2 RAC安装INS-35354问题一例
    为11.2.0.2 Grid Infrastructure添加节点
    修改/dev/shm的大小
  • 原文地址:https://www.cnblogs.com/sixloop/p/linux_packet_travel.html
Copyright © 2011-2022 走看看