netfilter与iptables & ufw与iptables关系

本篇主要来介绍一下 什么是netfilter ,iptables 以及两者的关系 什么是ufw ,以及ufw与iptables的关系

先给出一段英文文献供同学们阅读学习

Traffic into or out of a computer is filtered through “ports,” which are relatively arbitrary (任意的)designations(名称) appended to(附加到) traffic packets destined for(注定要) use by a particular application.
By convention(公约;惯例), some ports are routinely(例行公事地) used for particular types of applications. For example, port 80 is generally used for insecure web browsing and port 443 is used for secure web browsing.
Traffic to particular applications can be allowed or blocked by “opening” or “closing” (i.e. filtering) the ports designated for(指定为) a particular type of traffic. If port 80 is “closed,” for example, no (insecure) web browsing will be possible. The AntiVirus page might also be of interest.
The Linux kernel includes the netfilter(网络过滤器) subsystem(子系统), which is used to manipulate(操纵) or decide the fate of network traffic headed into or through your computer. All modern Linux firewall solutions use this arbitrarys(任意的) system for packet filtering.
The kernel’s packet filtering system would be of little use to users or administrators without a user interface(接口) with which to manage it. This is the purpose of iptables. When a packet reaches your computer, it is handed off (移交)to the netfilter subsystem for acceptance, manipulation, or rejection based on

评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值