Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

3
  • Thanks. Some commands seem to have the later-override-former model for overlapping rules, while some commands the first-win-over-latter model for overlapping rules . If I may ask, what kinds of commands are likely to use which model? Do you know any other models for resolving overlapping rules? Commented Mar 17, 2019 at 11:30
  • There’s no general rule. Models I can think of are “first match wins”, “last match wins”, “most specific wins”, I suppose one could imagine “least specific wins”; I don’t have examples off-hand for any of them. Commented Mar 17, 2019 at 13:23
  • Indeed, reading the man pages is one of the best ways. man iptables says "A firewall rule specifies criteria for a packet and a target. If the packet does not match, the next rule in the chain is the examined; if it does match, then the next rule is specified by the value of the target, which can be the name of a user-defined chain or one of the special values ... If the end of a built-in chain is reached or a rule in a built-in chain with target RETURN is matched, the target specified by the chain policy determines the fate of the packet. " Commented Mar 17, 2019 at 19:53