路由器连接输入tender_如何在路由决策输入默认值之前转移连接或数据包

路由器连接输入tender

before the packets ports (443) entering the firewall i would like to divert incoming packet of server (443) to input chain goes to FORWARD chain<br>
so thats the incoming packets 100.43.xx.xx –sport 443 are send it to FORWARD instead of input chain<br>
how to configure this in OUTPUT,FORWARD,POST AND PREROUTING CHAIN

在数据包端口(443)进入防火墙之前,我想将服务器 (443)的传入数据包转移到输入链,然后转到FORWARD chain <br>
这样就可以将传入数据包100.43.xx.xx –体育443发送给FORWARD而不是输入链<br>
如何在OUTPUT,FORWARD,POST和PREROUTING链中进行配置

and this is my nf_conntrack
tcp 6 431977 ESTABLISHED src=192.168.xx.xx dst=100.43.xx.xx sport=33575 dport=443

这是我的nf_conntrack
tcp 6 431977已建立src = 192.168.xx.xx dst = 100.43.xx.xx sport = 33575 dport = 443

src=100.43.xx.xx dst=192.168.xx.xx sport=443 dport=33575 [ASSURED] mark=0 use=1

tcp 6 431867 ESTABLISHED src=192.168.xx.xx dst=100.43.xx.xx sport=54461 dport=443

tcp 6 431867建立了src = 192.168.xx.xx dst = 100.43.xx.xx sport = 54461 dport = 443

src=100.43.xx.xx dst=192.168.xx.xx sport=443 dport=54461 [ASSURED] mark=0 use=1

my iptables rules<br>
root@kali:~# iptables-save</br>

我的iptables规则<br>
root @ kali:〜#iptables-保存</br>

Generated by iptables-save v1.4.21 on Sun Jan 14 15:20:35 2018

由iptables-save v1.4.21于2018年1月14日15:20:35生成

:PREROUTING ACCEPT [0:0]
:POSTROUTING ACCEPT [3409:2036610]
-A POSTROUTING -o wlan0 -m state –state NEW,RELATED,ESTABLISHED -j MASQUERADE

:接受[0:0]
:接受发布[3409:2036610]
-A POSTROUTING -o wlan0 -m状态–状态新,相关,已确定-j假面

filter
:INPUT ACCEPT [333:6760]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [333:6760]
-A INPUT -i wlan0 -p tcp -s 100.43.xx.xx –sport 443 -j DROP
-A INPUT -m state –state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -m state –state NEW,RELATED,ESTABLISHED -j ACCEPT

过滤
:输入接受[333:6760]
:正接受[0:0]
:输出接受[333:6760]
-A输入-i wlan0 -p tcp -s 100.43.xx.xx-运动443 -j DROP
-A输入-m状态-状态新,相关,已确定-j接受
-A输出-m状态-状态新,相关,已确定-j接受



If a packet is forwarded by iptables (e.g. by a rule in PREROUTING chain) https://www.systutorials.com/816/port-forwarding-using-iptables/ , it will go through the FORWARD chain.

如果数据包是由iptables转发的(例如,通过PREROUTING链中的规则) https://www.systutorials.com/816/port-forwarding-using-iptables/ ,则它将通过FORWARD链。

翻译自: https://www.systutorials.com/how-to-divert-connection-or-packet-before-routing-decision-entering-the-default/

路由器连接输入tender

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值