Iptables is used to set up, maintain, and inspect the tables of IP
packet filter rules in the Linux kernel. Several different tables may be
defined. Each table contains a number of built-in chains and may also contain
user-defined chains.
Each chain is a list of rules which can
match a set of packets. Each rule specifies what to do with a packet that
matches. This is called a 'target', which may be a
Targets
A firewall rule specifies criteria for a packet and a target. If the packet does not match, the next rule in the chain is the examined; if it does match, then the next rule is specified by the value of the target, which can be the name of a user-defined chain or one of the special values ACCEPT, DROP, QUEUE or RETURN.
ACCEPT means to let the packet through. DROP means to drop the packet on the floor. QUEUE means to pass the packet to user space.
(How the packet can be received by a user space process differs by the
particular queue handler. 2.4.x and 2.6.x kernels up to 2.6.13 include the ip_queue queue handler. Kernels 2.6.14 and
later additionally include the nfnetlink_queue queue handler. Packets with a target
of QUEUE will be sent to queue number '0' in this case. Please also see the NFQUEUE target as described later in this man page.) RETURN means stop traversing
this chain and resume at the next rule in the previous (calling) chain. If the
end of a built-in chain is reached or a rule in a built-in chain with target RETURN is matched, the target specified by
the chain policy determines the fate of the packet.