(As the basis of address translation, the connection tracking module in Netfilter has a deep understanding of the implementation mechanism of connection tracking based on the understanding of the implementation mechanism of Netfilter, which plays an important role in making full use of the functions of Netfilter framework and expanding other modules. This paper only briefly analyzes the overall framework of connection tracking, including the important data structures and functions, and roughly describes the connection tracking process of packet forwarding. The kernel source code analyzed is 2.6.21.2.)