Quote:
Originally posted by GnomeKing
<-- n00b btw, if u hadnt guessed :P
|
Same here I guess. I have been working with iptables for the past few days.
Quote:
uhhhh.... the only matches I've seen in dmesg is ext IP -> internet...
|
I gave it some more thought and I think it's like this:
LAN<->internet: PREROUTING(nat)->FORWARD(filter)->POSTROUTING(nat)
LAN/internet->firewall: PREROUTING(nat)->INPUT(filter)
firewall->LAN/internet: OUTPUT(nat)->OUTPUT(filter)->POSTROUTING(nat)
Quote:
why would internet -> firewall/lan pass through the natting table?....
|
Everything being sent goes through NAT (before or after routing or even both).
So my earlier remark was wrong.
The second rule catches internet->LAN, firewall->LAN and firewall->internet.
I hope I got this right. Is there anybody who can confirm this?