[arch-general] iptables forward policy

Corrado Primier ilbardo at gmail.com
Sat Aug 25 13:56:13 EDT 2012


2012/8/25 Juan Diego Tascón <juantascon at gmail.com>:
> Good day,

Hello :)

> I'm thinking of
> setting the default FORWARD policy to ACCEPT as my default INPUT
> policy is DROP and unless there is a valid FORWARD rule for a given
> port the packets wont go anywhere. I'm I right on this?

You're wrong. Either a packet goes through the INPUT chain or it goes
through the FORWARD chain, depending on its destination. Take a look
at this packet flow diagram:
http://www.linuxhomenetworking.com/wiki/images/f/f0/Iptables.gif

Corrado


More information about the arch-general mailing list