raw packets and iptables

Is it possible to build and transmit raw packets that iptables would
otherwise drop on that box?

For example, if the default policy on OUTPUT is to drop, and there's no rule
to allow outbound on port 'X', is it possible to build and send a raw packet
from port 'X', and bypass iptables, or will iptables still drop it?



1. raw socket packet and iptables

Hi, All,

        I want  to know how a raw packet passes the chain of iptables.

        Here are the iptables chains

        Conntrack    |       Filter   ^    NAT (Src)
        Mangle       |                |    Conntrack
        NAT (Dst)    |             [ROUTE]
        (QDisc)      v                |
                     IN Filter       OUT Conntrack
                     |  Conntrack     ^  Mangle
                     |                |  NAT (Dst)
                     v                |  Filter

        So how a raw packet go through these chains?


Xinwen Fu

