iptables Theory: Tables, Chains, and Targets

iptables is the traditional firewall management utility for Linux kernels. It operates by examining network packets as they pass through the network stack and applies a set of rules defined by the administrator. Understanding its core components—tables, chains, and targets—is fundamental to effectively configuring iptables.

1. Tables: Where Rules Reside

iptables organizes rules into different tables, each designed for a specific packet processing task. A packet traversing the network stack will typically pass through one or more tables.

  • filter Table (Default):
    • Purpose: The most commonly used table, responsible for packet filtering. It decides whether to ACCEPT, DROP, or REJECT a packet.
    • Usage: Mainly for filtering incoming (destined for the local machine), outgoing (originating from the local machine), and forwarded (passing through the machine) traffic.
  • nat Table:
    • Purpose: Used for Network Address Translation (NAT). It modifies the source or destination IP addresses and/or ports of packets.
    • Usage: Primarily for port forwarding, masquerading (SNAT), and redirecting traffic.
  • mangle Table:
    • Purpose: Used for modifying IP packet headers in various ways, such as altering the Quality of Service (QoS) bits.
  • raw Table:
    • Purpose: Used for connection tracking configuration. It can mark packets to be exempt from connection tracking.
  • security Table:
    • Purpose: Used for Mandatory Access Control (MAC) networking rules, like those enforced by SELinux.

2. Chains: Ordered Sequences of Rules

Each table contains predefined chains, which are ordered lists of rules that a packet is matched against. When a packet arrives, it traverses these chains sequentially based on its direction and destination.

filter Table Chains:

These chains control traffic flow to and from the local system and traffic being forwarded through it.

  • INPUT Chain:
    • Purpose: Processes packets destined for the local system.
    • Flow: Applied to packets arriving at the machine and intended for a local process.
  • OUTPUT Chain:
    • Purpose: Processes packets originating from the local system.
    • Flow: Applied to packets generated by a local process and leaving the machine.
  • FORWARD Chain:
    • Purpose: Processes packets that are not destined for the local system but are intended to be routed through it to another destination.
    • Flow: Applied to packets that pass through the machine (e.g., a router or gateway).

nat Table Chains:

These chains modify packet addresses (NAT) at different stages of their journey.

  • PREROUTING Chain:
    • Purpose: Modifies packets as they first arrive on a network interface, before any routing decisions are made.
    • Usage: Primarily for Destination NAT (DNAT), like port forwarding.
  • POSTROUTING Chain:
    • Purpose: Modifies packets just before they leave a network interface, after routing decisions have been made.
    • Usage: Primarily for Source NAT (SNAT), like masquerading.

3. Targets/Actions: What to Do with a Packet

When a packet matches a rule, iptables takes an action, known as a “target.”

  • ACCEPT: Allows the packet to pass through.
  • DROP: Silently discards the packet. The sender receives no notification.
  • REJECT: Discards the packet and sends an error message back to the sender (e.g., “port unreachable” or “host unreachable”). This informs the sender that the port is closed or the host is not reachable.
  • MASQUERADE: A specific type of SNAT primarily used in the nat table’s POSTROUTING chain. It replaces the source IP address of outgoing packets with the IP address of the outgoing interface, suitable for interfaces with dynamic IP addresses.
  • LOG: Logs information about the packet (e.g., to /var/log/kern.log or syslog) before letting it continue to the next rule. This is often used for auditing or debugging.
  • RETURN: Stops traversing the current chain and resumes at the next rule in the previous chain (the one that jumped to the current chain).
  • User-defined Chains: You can create custom chains (-N) and jump to them (-j <chain_name>) for better organization of rules.

Important Note on Rule Order: iptables processes rules sequentially within a chain. The order of rules is critical: once a packet matches a rule, the associated target is executed, and often (unless the target is LOG or a custom chain that RETURNs), no further rules in that chain are processed for that packet.