On Wednesday 14 May 2008 08:22:42 Fajar Priyanto wrote: > Hi all, > When we create a custom chain in iptables, should we specifically create a > rule to 'jump back' to the previous chain? > > For example: > iptables -A INPUT -j CUSTOMCHAIN > iptables -A CUSTOMCHAIN rule1 > iptables -A CUSTOMCHAIN rule2 > > Should we add: > iptables -A CUSTOMCHAIN -j INPUT ? Or, it will automatically go back to > CHAIN when there's no more rule? Ugh, I guess I'm answering myself. After reading the iptables doc more thoroughly (sorry), I found this: We could then add a jump target to it like this: iptables -A INPUT -p tcp -j tcp_packets We would then jump from the INPUT chain to the tcp_packets chain and start traversing that chain. When/If we reach the end of that chain, we get dropped back to the INPUT chain and the packet starts traversing from the rule one step below where it jumped to the other chain (tcp_packets in this case). Hope it's good for the archive. -- Fajar Priyanto | Reg'd Linux User #327841 | Linux tutorial http://linux2.arinet.org 08:58:23 up 1:51, 2.6.22-14-generic GNU/Linux Let's use OpenOffice. http://www.openoffice.org The real challenge of teaching is getting your students motivated to learn. -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 189 bytes Desc: This is a digitally signed message part. URL: <http://lists.centos.org/pipermail/centos/attachments/20080514/db2daa24/attachment-0005.sig>