Professional Documents
Culture Documents
xx
HotSpot Connection Mangle Configurable Facilities
Prerouting DST-NAT /ip firewall
In Tracking Prerouting
Filter Filter Filter Mangle Mangle
filter Input Forward Output Output Postrouting
Mangle Filter HTB Global Simple
Input
Input Input Queue tree Queues nat DST-NAT SRC-NAT
ROUTER LOCAL
Router
M Local Input
processes
Local Output N
no ROUTING
yes yes
Decapsulation
is needed? J K It's IP Traffic?
Network Layer
no
no
IPSec Routing IPSec
Policy Input
Decision Encryption
OUTPUT
INPUT
yes yes
IPSec Routing IPSec
Output Policy
Decryption Decision
no no
yes
It's IP Traffic? I Prerouting Forward Postrouting L
IP v4/v6 IP v4/v6 IP v4/v6 IP v4/v6
Header DATA FORWARD Header DATA
yes
VPLS or TE MPLS MPLS header
F G
(TE, VPLS, VLAN, Tunnel)
Encapsulation
OUTPUT no
INPUT
IN-INTERFACE OUT-INTERFACE
LOGICAL IN-INTERFACE OUT-INTERFACE LOGICAL
OUT
IN
PHYSICAL PHYSICAL
Physical Layer