Understanding Firewall/Packet Filtering on the OnBoard
64
AlterPath OnBoard Administrator’s Guide
Chains
A chain is a kind of named profile that includes one or more rules that define
the following:
•
A set of characteristics to look for in a packet
•
What to do with any packet that has all the defined characteristics
The OnBoard comes with a number of built-in chains with hidden rules that
are preconfigured to control communications between devices that are
connected to the OnBoard’s private Ethernet ports and devices on the public
side of the OnBoard. The default chains are defined in “filter” and “nat”
iptables
. The “mangle” table is not used.
The built-in chains are named according to the type of packets they handle, as
shown in the following lists. The first three chains listed below are in the
iptables
“filter” table.
•
INPUT
•
OUTPUT
•
FORWARD
The three chains listed below are in the “nat” table. These chains implement
NAT (network address translation) including the redirecting packets
addressed to a virtual IP to the device’s real IP address and hiding the device’s
real IP address when the device sends packets to the authorized user:
•
PREROUTING
•
POSTROUTING
•
OUTPUT
Rules
Each chain can have one or more rules that define the following:
•
The packet characteristics being filtered
The packet is checked for characteristics defined in the rule, for example,
a specific IP header, input and output interfaces, and protocol.
•
What to do when the packet characteristics match the rule
The packet is handled according to the specified action (called a “Rule
Target,” “Target Action” or “Policy”).
Summary of Contents for AlterPath OnBoard
Page 36: ...xxxvi AlterPath OnBoard Administrator s Guide...
Page 108: ...Understanding How Configuration Changes Are Handled 72 AlterPath OnBoard Administrator s Guide...
Page 116: ...Overview of Web Manager Menus 80 AlterPath OnBoard Administrator s Guide...
Page 146: ...Configuring Regular Users Wizard 110 AlterPath OnBoard Administrator s Guide...
Page 160: ...Upgrading AlterPath PM IPDU Software 124 AlterPath OnBoard Administrator s Guide...
Page 194: ...Configuring an Alternate Help File Location 158 AlterPath OnBoard Administrator s Guide...
Page 292: ...Configuring Private Subnets and Virtual Networks 256 AlterPath OnBoard Administrator s Guide...
Page 344: ...Using the create_cf Command When Troubleshooting 308 AlterPath OnBoard Administrator s Guide...