what is first checked by iptables? prerouting or input?

Philipp Snizek mailinglists@belfin.ch
Wed, 26 Sep 2001 10:40:08 +0200


Hi

First thanks to JVD who helped me with his answer yesterday. Logging works
fine now. Was a good tip with the user defined chains.

Imagine we had RFC 1918 addressed networks on both sides. Imagine further we
would combine -t nat and -t filter to one scheme (instead of 2 schemes as it
is in the how-tos).
Please just tell me whether this scheme is true:

--> prerouting --> input --> forward --> postrouting --->
                     |                |
                     |                |
                  local process -> output


Thank you
Philipp