18.12.7. Element and Attribute Overview
The root element required for all network filters is named
<filter>
with two possible attributes. The name
attribute provides a unique name of the given filter. The chain
attribute is optional but allows certain filters to be better organized for more efficient processing by the firewall subsystem of the underlying host physical machine. Currently the system only supports the following chains: root
, ipv4
, ipv6
, arp
and rarp
.