论文部分内容阅读
该文对Linux 9内核防火墙Iptables的原理进行了深入的研究,对NAT和iptables的概述及工作原理进行了分析比较,分析了在Iptables架构下防火墙的设计与实现,论述了企业内外网互访策略。文中涉及的企业内外网基于Iptables架构,运用其提供的HOOK函数接口连接内核的方法开发的包过滤的个人防火墙,测试达到了预期目标。该防火墙保护内部网络资源,防止内部信息泄漏和外部入侵,发现安全隐患,为安全策略的完善提供了帮助。
This paper deeply studies the principle of Linux 9 kernel firewall Iptables, analyzes and compares the overview and working principle of NAT and iptables, analyzes the design and implementation of firewall in Iptables architecture, . The internal and external networks involved in this paper are based on the Iptables architecture, using the packet filtering personal firewall developed by the HOOK function interfacing kernel method provided by the paper, and the testing achieves the expected goal. The firewall to protect the internal network resources, to prevent internal information leakage and external invasion, to find potential safety problems, to improve the security strategy has been helpful.