Section 15 - when to use NAT or Mangle tables?

I'm hoping someone can provide a scenario to illustrate when it would be appropriate to use an entry in the NAT table and when to use the Mangle table? And describing why that table was the appropriate choice. My interpretation is that there's some overlap in the chains that they target.
edit: is NAT outgoing traffic only?
Comments
-
I've been able to answer my own question after getting to the labs and checking the man page for
nft
┌───────┬──────────┬─────────────────────────────────────┬─────────────────────────────────────┐
│Type │ Families │ Hooks │ Description │
├───────┼──────────┼─────────────────────────────────────┼─────────────────────────────────────┤
│filter │ all │ all │ Standard chain type to use in │
│ │ │ │ doubt. │
├───────┼──────────┼─────────────────────────────────────┼─────────────────────────────────────┤
│nat │ ip, ip6 │ prerouting, input, output, │ Chains of this type perform Native │
│ │ │ postrouting │ Address Translation based on con‐ │
│ │ │ │ ntrack entries. Only the first │
│ │ │ │ packet of a connection actually │
│ │ │ │ traverses this chain - its rules │
│ │ │ │ usually define details of the cre‐ │
│ │ │ │ ated conntrack entry (NAT state‐ │
│ │ │ │ ments for instance). │
├───────┼──────────┼─────────────────────────────────────┼─────────────────────────────────────┤
│route │ ip, ip6 │ output │ If a packet has traversed a chain │
│ │ │ │ of this type and is about to be ac‐ │
│ │ │ │ cepted, a new route lookup is per‐ │
│ │ │ │ formed if relevant parts of the IP │
│ │ │ │ header have changed. This allows to │
│ │ │ │ e.g. implement policy routing se‐ │
│ │ │ │ lectors in nftables. │
└───────┴──────────┴─────────────────────────────────────┴─────────────────────────────────────┘0 -
Hi @GRO 108 ,
You also can take a look to the iptables man page:
https://ipset.netfilter.org/iptables.man.html
[...]
nat:
This table is consulted when a packet that creates a new connection is encountered. It consists of four built-ins: PREROUTING (for altering packets as soon as they come in), INPUT (for altering packets destined for local sockets), OUTPUT (for altering locally-generated packets before routing), and POSTROUTING (for altering packets as they are about to go out). IPv6 NAT support is available since kernel 3.7.mangle:
This table is used for specialized packet alteration. Until kernel 2.4.17 it had two built-in chains: PREROUTING (for altering incoming packets before routing) and OUTPUT (for altering locally-generated packets before routing). Since kernel 2.4.18, three other built-in chains are also supported: INPUT (for packets coming into the box itself), FORWARD (for altering packets being routed through the box), and POSTROUTING (for altering packets as they are about to go out).Regards,
Luis.0 -
Some example uses of the mangle table are altering elements of the packet header like TTL or mtu. These are usually specialized cases. There are additional tables that fall int the specialized category such as "security" and "raw" . Netfilter is very flexible and feature rich so there are many options that can be used.
0
Categories
- 10.1K All Categories
- 35 LFX Mentorship
- 88 LFX Mentorship: Linux Kernel
- 502 Linux Foundation Boot Camps
- 278 Cloud Engineer Boot Camp
- 103 Advanced Cloud Engineer Boot Camp
- 47 DevOps Engineer Boot Camp
- 41 Cloud Native Developer Boot Camp
- 2 Express Training Courses
- 2 Express Courses - Discussion Forum
- 1.7K Training Courses
- 17 LFC110 Class Forum
- 4 LFC131 Class Forum
- 19 LFD102 Class Forum
- 148 LFD103 Class Forum
- 12 LFD121 Class Forum
- 61 LFD201 Class Forum
- LFD210 Class Forum
- 1 LFD213 Class Forum - Discontinued
- 128 LFD232 Class Forum
- 23 LFD254 Class Forum
- 568 LFD259 Class Forum
- 100 LFD272 Class Forum
- 1 LFD272-JP クラス フォーラム
- 1 LFS145 Class Forum
- 22 LFS200 Class Forum
- 739 LFS201 Class Forum
- 1 LFS201-JP クラス フォーラム
- 1 LFS203 Class Forum
- 45 LFS207 Class Forum
- 298 LFS211 Class Forum
- 53 LFS216 Class Forum
- 46 LFS241 Class Forum
- 41 LFS242 Class Forum
- 37 LFS243 Class Forum
- 10 LFS244 Class Forum
- 27 LFS250 Class Forum
- 1 LFS250-JP クラス フォーラム
- 131 LFS253 Class Forum
- 994 LFS258 Class Forum
- 10 LFS258-JP クラス フォーラム
- 87 LFS260 Class Forum
- 126 LFS261 Class Forum
- 31 LFS262 Class Forum
- 79 LFS263 Class Forum
- 15 LFS264 Class Forum
- 10 LFS266 Class Forum
- 17 LFS267 Class Forum
- 17 LFS268 Class Forum
- 21 LFS269 Class Forum
- 200 LFS272 Class Forum
- 1 LFS272-JP クラス フォーラム
- 212 LFW211 Class Forum
- 153 LFW212 Class Forum
- 899 Hardware
- 217 Drivers
- 74 I/O Devices
- 44 Monitors
- 115 Multimedia
- 208 Networking
- 101 Printers & Scanners
- 85 Storage
- 749 Linux Distributions
- 88 Debian
- 64 Fedora
- 14 Linux Mint
- 13 Mageia
- 24 openSUSE
- 133 Red Hat Enterprise
- 33 Slackware
- 13 SUSE Enterprise
- 355 Ubuntu
- 473 Linux System Administration
- 38 Cloud Computing
- 69 Command Line/Scripting
- Github systems admin projects
- 94 Linux Security
- 77 Network Management
- 108 System Management
- 49 Web Management
- 63 Mobile Computing
- 22 Android
- 27 Development
- 1.2K New to Linux
- 1.1K Getting Started with Linux
- 527 Off Topic
- 127 Introductions
- 213 Small Talk
- 19 Study Material
- 794 Programming and Development
- 262 Kernel Development
- 498 Software Development
- 922 Software
- 257 Applications
- 182 Command Line
- 2 Compiling/Installing
- 76 Games
- 316 Installation
- 53 All In Program
- 53 All In Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)