返回列表 發帖

Firewall/Router Vs iptables/route

在学习iptables/route中慢慢理解firewall与router的分别,之前都不太会分开两者的关系。

如果要知道两者(Firewall和Router)的分别,那么我们要先从iptables和route两个指令的功能开始说起。

Firewall (iptables指令),就是packets进入和离开一个盒子的manipulation(管制)。

Router(route指令),就是怎样把盒子两边的newtwork连起来。

TOP

本帖最後由 角色 於 2013-12-7 11:02 編輯

In [1], a router is designed to route data packets from one interface to another. A firewall inspects the data packets and adds filtering and blocking of data packets with services like NAT

Think of a traffic cop at an intersection. He will carefully and decisively direct the traffic the direction it needs to go, this is a router.

You have another cop that has a gun. He does not care where the traffic is going, he just wants to know what the traffic is doing. If it is "bad" then he will shoot that "blocked" traffic onsite and toss it in the bit bucket. This would be a firewall.

Now take the traffic cop and give him the gun. He will now direct traffic as well as make sure it is "good". He is now a router/firewall.

References
[1] http://community.spiceworks.com/ ... at-s-the-difference

TOP

返回列表