netfilter五个hook点分别是:
NF_INIT_PRE_ROUTING
NF_INIT_LOCAL_IN
NF_INIT_FORWARD
NF_INIT_LOCAL_OUT
NF_INIT_POST_ROUTING
大致流程:
ip_local_deliver -->LOCAL IN-->ip_local_deliver_finish
/
ip_rcv --> PRE ROUTING --> ip_rcv_finish -- >ip_forword
\
ip_forword -->FORWORD--> ip_forward_finish--> ip_finish_output --> ip_output -->POST ROUTING
__ip_local_out --> LOCAL OUT --> ip_output -->POST ROUTING