ChinaUnix.net
Ïà¹ØÎÄÕÂÍÆ¼ö:

linuxÖÐnetfilterµÄÔ­Àí

netfilterÊÇÒ»ÖÖÄÚºËÖÐÓÃÓÚÀ©Õ¹¸÷ÖÖÍøÂç·þÎñµÄ½á¹¹»¯µ×²ã¿ò¼Ü¡£netfilterµÄÉè¼ÆË¼ÏëÊÇÉú³ÉÒ»¸öÄ£¿é½á¹¹Ê¹Ö®Äܹ»±È½ÏÈÝÒ×µÄÀ©Õ¹¡£ÐµÄÌØÐÔ¼ÓÈëµ½ÄÚºËÖв¢²»ÐèÒª´ÓÐÂÆô¶¯Äںˡ£ÕâÑù£¬¿ÉÒÔͨ¹ý¼òµ¥µÄ¹¹ÔìÒ»¸öÄÚºËÄ£¿éÀ´ÊµÏÖÍøÂçÐÂÌØÐÔµÄÀ©Õ¹¡£¸øµ×²ãµÄÍøÂçÌØÐÔÀ©Õ¹´øÀ´Á˼«´óµÄ±ãÀû£¬Ê¹¸ü¶à´ÓÊÂÍøÂçµ×²ãÑз¢µÄ¿ª·¢ÈËÔ±Äܹ»¼¯Öо«Á¦ÊµÏÖеÄÍøÂçÌØÐÔ¡£ netfilterÓÐ4´óÌØÐÔ£º ¡¡1£® ÿһ¸öЭÒ鶨Òå"hooks"£¨¹³×Ó£©£¬IPv4¶¨ÒåÁË5¸ö¹³×Ó...

by ¶«·½ÀöÈË - ÍøÂç¼¼ÊõÎĵµÖÐÐÄ - 2006-11-01 10:17:48 ÔĶÁ£¨706£© »Ø¸´£¨0£©

Ïà¹ØÌÖÂÛ

linux2.6.17ÖÐbr.cÎļþÏÂbr_netfilter_init()º¯ÊýÊÇ×öʲôÓõÄ?

by lib_net - ÄÚºË/ǶÈë¼¼Êõ - 2006-08-24 11:16:23 ÔĶÁ£¨335£© »Ø¸´£¨0£©

ÔÚʵʩnetfilterµÄnatÓ¦ÓÃʱ,Õâ¸öÎÊÌâÒ»Ö±Ïë²»Çå³þ: ÎÞÂÛÊÇSNAT»¹ÊÇDNAT,µ±Ä³¸ö·ÓÉÁ¬½ÓµÄµÚÒ»¸öÇëÇóÊý¾Ý°üͨ¹ýnetfilterʱ,ÎÒ¿ÉÒÔÀí½âҪͨ¹ý NETWORK-->(mangle)PREROUTING-->(nat)PREROUTING-->·ÓÉ??-->(mangle)FORWARD-->(filter)FORWARD-->(mangle)POSTROUTING-->(nat)POSTROUTING-->NETWORK,ÕâʱSNATÔÚ(nat)POSTROUTING±»·­Òë¶øDNATÔÚ(nat)PREROUTING·­Òë. ÄÇô»ØÓ¦°üÊÇÈçºÎͨ¹ýÕâ¸öÁ´?ËûµÄÔ´µØÖ·»òÄ¿µÄµØÖ·ÊÇÔÚÄÇÒ»...

by MiniLin - ÍøÂçÓëÓ²¼þ - 2006-11-03 11:51:43 ÔĶÁ£¨585£© »Ø¸´£¨0£©

netfilterÖÐÒ»¸öHookµã×¢²áÁ˶à¸öHook£¬hookº¯ÊýµÄ·µ»ØÖµÖÐÓÐûÓпÉÒÔÖ¸¶¨¾­¹ýÁ˸Ãhook´¦Àíºó£¬ºóÐøhookÎÞÐè´¦Àí£¬Ö±½Ó½øÐÐÆäËû´¦ÀíµÄ£¿

by yy_unicorn - ÄÚºË/ǶÈë¼¼Êõ - 2006-08-10 16:31:15 ÔĶÁ£¨614£© »Ø¸´£¨1£©

ÄÇλÑо¿¹ýnetfilterµÄÇ뽲һϠnetfilterʵÏÖÔ­Àí.

by lib_net - ÄÚºË/ǶÈë¼¼Êõ - 2006-08-21 15:43:05 ÔĶÁ£¨456£© »Ø¸´£¨1£©

±¾ÎĵµµÄCopyleft¹éyfydzËùÓУ¬Ê¹ÓÃGPL·¢²¼£¬¿ÉÒÔ×ÔÓÉ¿½±´£¬×ªÔØ£¬×ªÔØÊ±Çë±£³ÖÎĵµµÄÍêÕûÐÔ£¬ÑϽûÓÃÓÚÈκÎÉÌÒµÓÃ;¡£ msn: [email=yfydz_no1@hotmail.com]yfydz_no1@hotmail.com[/email] À´Ô´£º http://yfydz.cublog.cn 1. 5¸ö¹Ò½Óµã ÒÔÏÂÄں˴úÂë°æ±¾2.6.17.11¡£ 1.1 PREROTING /* net/ipv4/ip_input.c */ int ip_rcv(struct sk_buff *skb, struct net_device *dev, struct packet_type *pt, struct net_device *orig_dev) { ....

by where23 - ÍøÂç¼¼ÊõÎĵµÖÐÐÄ - 2009-04-04 11:24:17 ÔĶÁ£¨1028£© »Ø¸´£¨0£©

¸Õ¿´iptables,ÏÖÔÚÎÒÏë×öÒ»¸öС¹¦ÄÜ£¬¾ÍÊǼòµ¥µÄ½øÐÐURL filter£¬¾Ù¸ö¼òµ¥µÄÀý×Ó£¬ÎÒÏÖÔÚÒª¶Ôsohu.com½øÐÐÀ¹½Ø£¬ÄÇôÎÒÔõôÔÚÎÒµÄnetfilterÖÐдiptablesµÄ¹æÔòÄØ£¿£¿ ÆäʵÕâ¸öµØ·½¾ÍÊǽøÐаüµÄÄÚÈݽøÐбȽÏÁË£¨×Ö·û´®£©£¬ÓÐʲôÓï¾äÄÜÕâÑù×öÄØ£¡ÊDz»ÊÇ»¹ÓÐʲôģ¿é£¬»¹ÊÇÒª×Ô¼ºÐ´£¡Ï£ÍûÄÜÈ˰ïСµÚÒ»°Ñ£¡ ·Ç³£¸Ðл£¡ [ ±¾Ìû×îºóÓÉ heizi_liu ÓÚ 2006-12-13 16:00 ±à¼­ ]

by heizi_liu - ÄÚºË/ǶÈë¼¼Êõ - 2006-12-13 20:04:28 ÔĶÁ£¨686£© »Ø¸´£¨1£©

ÎÒÏëÔÚnetfilterÖйҽÓÒ»¸öÊý¾Ý°üת·¢º¯Êý£¬¶ÔÓÚTCP°ü£¬ÎÒÏë´¦ÀíÈý´ÎÎÕÊÖÖ®ºóµÄµÚÒ»¸öÊý¾Ý°ü£¬Èý´ÎÎÕÊֵijÌÐòÊÇlinuxÄÚºË×Ô¶¯ÔËÐе쬻¹ÊÇÐèÒª×Ô¼º±à³Ì£¿

by wzwhh - ÄÚºË/ǶÈë¼¼Êõ - 2005-07-16 11:06:45 ÔĶÁ£¨438£© »Ø¸´£¨0£©

µ«ÎÒû¿´µ½netfilterµÄ°²×°°üѽ£¿ÈçºÎÉý¼¶ÄØ£¿

by oldcaption - ϵͳ¹ÜÀí - 2004-08-16 16:38:08 ÔĶÁ£¨415£© »Ø¸´£¨2£©

Äܲ»ÄÜÔÚÕâ¸önetfilterµÄ»·¾³ÖÐʹÓÃkmalloc·ÖÅäÄڴ棿Èç¹û¿ÉÒÔ£¬ÐèҪʹÓÃʲôÑùµÄflag£¿

by yy_unicorn - ÄÚºË/ǶÈë¼¼Êõ - 2006-08-24 11:26:30 ÔĶÁ£¨405£© »Ø¸´£¨0£©

³õ´Î½Ó´¥netfilterÔ´Âë, ¶ÔÕâÁ½¸ö·µ»ØÖµµÄÀí½â²»´óÃ÷°×.¹ÊÏò¸÷λ´óϺÇë½Ì. 1. NF_REPEAT: netfilter.cÖÐ static unsigned int nf_iterate(struct list_head *head, struct sk_buff **skb, int hook, const struct net_device *indev, const struct net_device *outdev, struct list_head **i, int (*okfn)(struct sk_buff *)) { for (*i = (*i)->next; *i != head;...

by ipt_ids - Êý¾Ý°²È« - 2008-06-14 18:06:13 ÔĶÁ£¨1711£© »Ø¸´£¨3£©