LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-14-2014, 09:57 PM   #1
learning01
LQ Newbie
 
Registered: Jul 2012
Posts: 10

Rep: Reputation: Disabled
IPTables Packet handling


Hi,

I have been trying to figure out how would I be able to setup iptables to forward original or copy of packets to an another filtering system for additional filtering

example:

--- Packet ---> [IPTables-Pre-State] ---> [Additional Filter] ---> [IPTables-Post-State]

OR

--- Packet --> [IPTables-Pre-State] ---> [IPTables-Post-State] --> [Copy send to Additional Filtering System as well as out the interface]

I wanted to try few things in my spare time to build an open-source filter based on L7 by reading the packets content and adjusting the IPTables Rule on a as-needed basis where an application is allowed or not...

similar to what ngfw are doing

thanks
 
Old 03-15-2014, 10:55 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by learning01 View Post
I have been trying to figure out how would I be able to setup iptables to forward original or copy of packets to an another filtering system for additional filtering (..) I wanted to try few things in my spare time to build an open-source filter based on L7 by reading the packets content and adjusting the IPTables Rule on a as-needed basis where an application is allowed or not...
Well basically you would use the nfnetlink protocol just like L7 uses. Also see the Python and Perl bindings for libnetfilter_queue: https://www.wzdftpd.net/redmine/proj...-bindings/wiki
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables packet filtering issue ? How iptables working. pradiptart Linux - Networking 3 02-13-2014 02:16 AM
onboard vs pci packet handling Geoff_Mac Linux - Networking 3 11-29-2011 07:12 AM
Lipipq(iptables) . How do I redirect captured packet to another address with iptables inet905 Programming 0 05-25-2010 02:20 AM
iptables good packet chain (instead of bad packet chain) win32sux Linux - Security 6 11-06-2008 07:02 AM
packet handling at the kernel level valib4u *BSD 4 09-14-2003 04:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration