One Unified Global Perspective
Communications with a Global Perspective
Home
Intro
Contact Us
Voice over IP
PBX Solutions
Services
Support
Glossary
Open Source
Blog
Forum

WebMail





2007 Mar 15 - Thu

NetFilter Documentation, Tutorial and Pictures

The packet flow through netfilter has been a little hazy for me. Today I received enlightenment. Pablo Neira Ayuso has a paper called Towards 4th Generation Linux Firewalling Tools. On page 10 of that presentation is an excellent drawing of the iptables paths and what is performed in each path. It clearly shows PREROUTING, FORWARD, INPUT, OUTPUT, and POSTROUTING.

In the cross references on that page are a couple of good links:

While here, and on an unrelated topic, here is a Packet Shaping HOWTO. Now if I could just find a utility that can chart who is doing what with what protocol in real time. In isn't open source but later I did come across ObjectPlanent's Net Probe as something that could do the job.

Here are a few interesting commands to use when iptables is active:

  • cat /proc/net/dev
  • cat /proc/net/netstat
  • cat /proc/net/ip_conntrack
  • cat /proc/net/sockstat
  • iptables --list -v

A paper called Netfilter Performance Testing is a good one which discusses the testing of netfilter and the various tools employed to do so.

The NetFilter site is at www.netfilter.org. For monitoring connections conntrack, ulogd2, and libnetfilter_conntrack are projects to look at.

Intellos Network has a souped up Conntrack Viewer for 2.4 kernels. I wander if it will work on 2.6 kernels.

Some background information on network accounting with netfilter and userspace utilities.



Blog Content ©2008
Ray Burkholder
All Rights Reserved
ray@oneunified.net
(441) 505 7293
Available for Contract Work
Resume

RSS: Click to see the XML version of this web page.

View Ray 
Burkholder's profile on LinkedIn
technorati
Add to Technorati Favorites



March
Su Mo Tu We Th Fr Sa
       
15


Main Links:
Monitoring Server
SSH Tools
QuantDeveloper Code

Special Links:
Frink

Blog Links:
Sergey Solyanik
Marc Andreessen
HotGigs
Micro Persuasion
... Reasonable ...
Chris Donnan
BeyondVC
lifehacker
Trader Mike
Ticker Sense
HeadRush
TraderFeed
Stock Bandit
The Daily WTF
Guy Kawaski
J. Brant Arseneau
Steve Pavlina
Matt Cutts
Kevin Scaldeferri
Joel On Software
Quant Recruiter
Blosxom User Group
Wesner Moise
Julian Dunn
Steve Yegge

2007
Months
Mar




Mason HQ

Disclaimer: This site may include market analysis. All ideas, opinions, and/or forecasts, expressed or implied herein, are for informational purposes only and should not be construed as a recommendation to invest, trade, and/or speculate in the markets. Any investments, trades, and/or speculations made in light of the ideas, opinions, and/or forecasts, expressed or implied herein, are committed at your own risk, financial or otherwise.