®Ö¤ß±q 'filter' ªí®æªº¤TÓ¦Cªí(lists) ¶}©l¡Q³o¤TÓ¦Cªí¥s°µ firewall chains(¨¾¤õÀðÃì) ©Î´N¥s chains(Ãì)¡C ³o¤TÓÃì¤À§O¬°INPUT¡NOUTPUT ¡N©M FORWARD ¡C
³o¸ò 2.0 ©M 2.2 ®Ö¤ß¦³«Ü¤j®t§O®@¡T
¹ï©ó ASCII ÃÀ³N°g¨Ó»¡¡M¦UÃì(chains)ªº§G¸m¦p¤U¡R
_____ Incoming / \ Outgoing -->[Routing ]--->|FORWARD|-------> [Decision] \_____/ ^ | | v ____ ___ / \ / \ |OUTPUT| |INPUT| \____/ \___/ ^ | | ----> Local Process ----
¨ä¤¤¤TÓ°é¥NªíµÛ«ezªº¤TÓÃì¡M·í¤@Ó«Ê¥]©è¹F¤W¹Ï¤¤ªº¨ä¤¤¤@Ó°é¡M¬ÛÀ³ªºÃì´N·|±µ¨üÀËÅç(examined)¡M¥H¨M©w¨ºÓ«Ê¥]ªº©R¹B¡C¦pªGÃ컡 DROP ±¼³oÓ«Ê¥]¡M¨º»ò¥¦´N·|´N¦a¥¿ªk¡M¦ý¦pªGÃ컡 ACCEPT ³oÓ«Ê¥]¡M¨º»ò¥¦´NÄ Äò¦b¹Ï¥Ü¤¤¬ï¶V¡C
¤@ÓÃì(chain)¨ä¹ê´N¬O²³¦h³W«h(rules)¤¤ªº¤@ÓÀˬd²M³æ(checklist)¡C¨C¤@±ø³W«h³£·|»¡¡§¦pªG«Ê¥]ªíÀY¬Ý°_¨Ó¹³³o¼Ë¡M´N¦p¦¹³o¯ë³B¸m³oÓ«Ê¥]¡¨¡C¦pªG³W«hªº³]©w©M«Ê¥]¨Ã¤£²Å¦X(match)¡M¨º»ò´N¥æ¥ÑÃ줤ªº¤U¤@Ó³W«hÄ Äò³B²z¡C¦Ó³Ì²×¡M¦pªG¦A¨S¦³³W«h¥i¥H°Ñ¦Ò¡M¨º»ò®Ö¤ß´N·|¬ÝÃ쪺policy(ì«h) ¥H¨M©w«ç»ò°µ¡C¦b¤@Ó¦w¥þ¦Ü¤Wªº¨t²Î¸Ì¡Mì«h(policy)³q±`³£·|§i¶D®Ö¤ß DROP ±¼¸Ó«Ê¥]¡C