目录
文章目录
netfilter 框架
Netfilter is a framework provided by the Linux kernel that allows various networking-related operations to be implemented in the form of customized handlers. Netfilter offers various functions and operations for packet filtering, network address translation, and port translation, which provide the functionality required for directing packets through a network and prohibiting packets from reaching sensitive locations within a network.
netfilter 是 Linux Kernel 中的一个对数据包进行控制、修改和过滤(Manipulation and Filtering)的框架。netfilter 是最古老的内核框架之一,自 1998 年开始开发,2000 年合并到 2.4.x 内核主线版本中。
netfilter 在 Kernel TCP/IP Stack L3 Layer 实现中设置了若干 Hook