路由器连接输入tender
before the packets ports (443) entering the firewall i would like to divert incoming packet of server (443) to input chain goes to FORWARD chain<br>
so thats the incoming packets 100.43.xx.xx –sport 443 are send it to FORWARD instead of input chain<br>
how to configure this in OUTPUT,FORWARD,POST AND PREROUTING CHAIN
在数据包端口(443)进入防火墙之前,我想将服务器 (443)的传入数据包转移到输入链,然后转到FORWARD chain <br>
这样就可以将传入数据包100.43.xx.xx –体育443发送给FORWARD而不是输入链<br>
如何在OUTPUT,FORWARD,POST和PREROUTING链中进行配置
and this is my nf_conntrack
tcp 6 431977 ESTABLISHED src=192.168.xx.xx dst=100.43.xx.xx sport=33575 dport=443
这是我的nf_conntrack
tcp 6 431977已建立src = 192.168.xx.xx dst = 100.43.xx.xx sport = 33575 dport = 443
src=100.43.xx.xx dst=192.168.xx.xx sport=443 dport=33575 [ASSURED] mark=0 use=1
tcp 6 431867 ESTABLISHED src=192.168.xx.xx dst=100.43.xx.xx sport=54461 dport=443
tcp 6 431867建立了src = 192.168.xx.xx dst = 100.43.xx.xx sport = 54461 dport = 443
src=100.43.xx.xx dst=192.168.xx.xx sport=443 dport=54461 [ASSURED] mark=0 use=1
my iptables rules<br>
root@kali:~# iptables-save</br>
我的iptables规则<br>
root @ kali:〜#iptables-保存</br>
Generated by iptables-save v1.4.21 on Sun Jan 14 15:20:35 2018
由iptables-save v1.4.21于2018年1月14日15:20:35生成
:PREROUTING ACCEPT [0:0]
:POSTROUTING ACCEPT [3409:2036610]
-A POSTROUTING -o wlan0 -m state –state NEW,RELATED,ESTABLISHED -j MASQUERADE
:接受[0:0]
:接受发布[3409:2036610]
-A POSTROUTING -o wlan0 -m状态–状态新,相关,已确定-j假面
filter
:INPUT ACCEPT [333:6760]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [333:6760]
-A INPUT -i wlan0 -p tcp -s 100.43.xx.xx –sport 443 -j DROP
-A INPUT -m state –state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -m state –state NEW,RELATED,ESTABLISHED -j ACCEPT
过滤
:输入接受[333:6760]
:正接受[0:0]
:输出接受[333:6760]
-A输入-i wlan0 -p tcp -s 100.43.xx.xx-运动443 -j DROP
-A输入-m状态-状态新,相关,已确定-j接受
-A输出-m状态-状态新,相关,已确定-j接受
If a packet is forwarded by iptables (e.g. by a rule in PREROUTING chain) https://www.systutorials.com/816/port-forwarding-using-iptables/ , it will go through the FORWARD chain.
如果数据包是由iptables转发的(例如,通过PREROUTING链中的规则) https://www.systutorials.com/816/port-forwarding-using-iptables/ ,则它将通过FORWARD链。
路由器连接输入tender