- 论坛徽章:
- 0
|
[img][/img]
Locally originated frames will, after the bridging decision, traverse the nat OUTPUT, the filter OUTPUT and the nat POSTROUTING chains. The nat OUTPUT chain allows to alter the destination MAC address and the filter OUTPUT chain allows to filter frames originating from the bridge box. Note that the nat OUTPUT chain is traversed after the bridging decision, so this is actually too late. We should change this. The nat POSTROUTING chain is the same one as described above.
是由于红色字体所述的原因么,那么这样的话,在哪里去匹配本地发出的包呢?
[ 本帖最后由 hedandi 于 2008-7-17 13:40 编辑 ] |
|