@
luckypoem 我是说理论上,像这个人问的。。
http://lists.netfilter.org/pipermail/netfilter/2003-June/045010.html> If I understand correctly, there are two parts of iptables,
> kernel space and user space and what we use in the RPM is
> only user space. It need the kernel space change compiled
> into the kernel, e.g. Linux. If so, does anyone know if
> the Mac OS kernel, based on BSD I believe, supports the user
> space part of the iptables?
iptables 不仅是有它自己的代码实现,它还依靠了内核特性啊。。