CLI (or GUI – knetfilter, smoothwall etc) instructs userland application (iptables) to query the filtering subsystem of the kernel (netfilter)