{"id":106246,"date":"2022-12-23T15:36:42","date_gmt":"2022-12-23T13:36:42","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-1-0-6"},"modified":"2022-12-23T15:36:42","modified_gmt":"2022-12-23T13:36:42","slug":"vypusk-paketnogo-filtra-nftables-1-0-6","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-paketnogo-filtra-nftables-1-0-6","title":{"rendered":"Ver\u00f6ffentlichung des Paketfilters nftables 1.0.6.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Die Ausgabe des Paketfilters nftables 1.0.6 wurde ver\u00f6ffentlicht, der die Schnittstellen zur Paketfilterung f\u00fcr IPv4, IPv6, ARP und netzwerkbridges vereinheitlicht (zielt darauf ab, iptables, ip6tables, arptables und ebtables zu ersetzen). Das Paket nftables enth\u00e4lt Komponenten des Paketfilters, die im Benutzermodus arbeiten, w\u00e4hrend im Kernel die nf_tables-Untersystem, die seit Version 3.13 Teil des Linux-Kernels ist, die Funktionalit\u00e4t bereitstellt. Im Kernel wird lediglich eine allgemeine Schnittstelle bereitgestellt, die unabh\u00e4ngig vom spezifischen Protokoll ist und grundlegende Funktionen zum Extrahieren von Daten aus Paketen, zur Durchf\u00fchrung von Datenoperationen und zur Steuerung des Datenflusses bietet.    <\/p>\n<p>Die eigentlichen Filterregeln und protokollspezifischen Handler werden im Benutzermodus in Bytecode kompiliert, danach wird dieser Bytecode \u00fcber die Netlink-Schnittstelle in den Kernel geladen und dort in einem speziellen <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/vps\/abuzoustojchivye-vps\/\"   title=\"virtuellen Maschine\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4332\">virtuellen Maschine<\/a>, der an BPF (Berkeley Packet Filters) erinnert, ausgef\u00fchrt. Dieser Ansatz erm\u00f6glicht es, die Gr\u00f6\u00dfe des im Kernel arbeitenden Filtercodes erheblich zu reduzieren und alle Funktionen zur Regel-Parsing und zur Logik der Protokollverarbeitung in den Benutzermodus auszulagern.    <\/p>\n<p>Haupt\u00e4nderungen:  <\/p>\n<ul>\n<li class=\"l\"> Im Regelsatzoptimierer, der durch die Option &#171;-o\/&#8212;optimize&#187; aufgerufen wird, ist eine automatische Regelkompression durch deren Zusammenf\u00fchrung und Umwandlung in Map- und Set-Listen etabliert. Zum Beispiel werden die Regeln         # cat ruleset.nft       table ip x {              chain y {                     type filter hook input priority filter; policy drop;                     meta iifname eth1 ip saddr 1.1.1.1 ip daddr 2.2.2.3 accept                     meta iifname eth1 ip saddr 1.1.1.2 ip daddr 2.2.2.4 accept                     meta iifname eth1 ip saddr 1.1.1.2 ip daddr 2.2.3.0\/24 accept                     meta iifname eth1 ip saddr 1.1.1.2 ip daddr 2.2.4.0-2.2.4.10   accept                     meta iifname eth2 ip saddr 1.1.1.3 ip daddr 2.2.2.5 accept              }       }    nach der Ausf\u00fchrung von &#171;nft -o -c -f ruleset.nft&#187; in folgender Weise umgewandelt:         ruleset.nft:4:17-74:                 meta iifname eth1 ip saddr 1.1.1.1 ip   daddr 2.2.2.3 accept       ruleset.nft:5:17-74:                 meta iifname eth1 ip saddr 1.1.1.2 ip   daddr 2.2.2.4 accept       ruleset.nft:6:17-77:                 meta iifname eth1 ip saddr 1.1.1.2 ip   daddr 2.2.3.0\/24 accept       ruleset.nft:7:17-83:                 meta iifname eth1 ip saddr 1.1.1.2 ip   daddr 2.2.4.0-2.2.4.10 accept       ruleset.nft:8:17-74:                 meta iifname eth2 ip saddr 1.1.1.3 ip   daddr 2.2.2.5 accept       in:               iifname . ip saddr . ip daddr { eth1 . 1.1.1.1 . 2.2.2.3, eth1 .   1.1.1.2 . 2.2.2.4, eth1 . 1.1.1.2 . 2.2.3.0\/24, eth1 . 1.1.1.2 .   2.2.4.0-2.2.4.10, eth2 . 1.1.1.3 . 2.2.2.5 } accept\n<li class=\"l\"> Der Optimierer kann auch Regeln in einer kompakteren Form umwandeln, in der bereits einfache Set-Listen verwendet werden, beispielsweise die Regeln:         # cat ruleset.nft       table ip filter {              chain input {                     type filter hook input priority filter; policy drop;                     iifname &#171;lo&#187; accept                     ct state established,related accept comment &#171;In traffic we   originate, we trust&#187;                     iifname &#171;enp0s31f6&#187; ip saddr { 209.115.181.102,   216.197.228.230 } ip daddr 10.0.0.149 udp sport 123 udp dport 32768-65535 accept                     iifname &#171;enp0s31f6&#187; ip saddr { 64.59.144.17, 64.59.150.133 }   ip daddr 10.0.0.149 udp sport 53 udp dport 32768-65535 accept             }       }    nach der Ausf\u00fchrung von &#171;nft -o -c -f ruleset.nft&#187; werden folgende Packungen erreicht:         ruleset.nft:6:22-149:                      iifname &#171;enp0s31f6&#187; ip saddr {   209.115.181.102, 216.197.228.230 } ip daddr 10.0.0.149 udp sport 123 udp dport   32768-65535 accept       ruleset.nft:7:22-143:                      iifname &#171;enp0s31f6&#187; ip saddr {   64.59.144.17, 64.59.150.133 } ip daddr 10.0.0.149 udp sport 53 udp dport   32768-65535 accept       in:                  iifname . ip saddr . ip daddr . udp sport . udp dport {   enp0s31f6 . 209.115.181.102 . 10.0.0.149 . 123 . 32768-65535, enp0s31f6 .   216.197.228.230 . 10.0.0.149 . 123 . 32768-65535, enp0s31f6 . 64.59.144.17 .   10.0.0.149 . 53 . 32768-65535, enp0s31f6 . 64.59.150.133 . 10.0.0.149 . 53 .   32768-65535 } accept\n<li class=\"l\"> Das Problem der Bytecode-Generierung zur Zusammenf\u00fchrung von Intervallen, in denen Typen mit unterschiedlicher Byte-Reihenfolge verwendet werden, zum Beispiel IPv4 (Netzwerk-Byte-Reihenfolge) und meta mark (systematische Byte-Reihenfolge), wurde gel\u00f6st.        table ip x {             map w {                   typeof ip saddr . meta mark : verdict                   flags interval                   counter                   elements = {                           127.0.0.1-127.0.0.4 . 0x123434-0xb00122 : accept,                           192.168.0.10-192.168.1.20 . 0x0000aa00-0x0000aaff :   accept,                   }            }            chain k {                   type filter hook input priority filter; policy drop;                   ip saddr . meta mark vmap @w            }      }\n<li class=\"l\"> Die Zuordnung seltener Protokolle bei der Verwendung von Raw-Ausdr\u00fccken wurde eingerichtet, zum Beispiel:         meta l4proto 91 @th,400,16 0x0 accept\n<li class=\"l\"> Die Probleme beim Einf\u00fcgen von Regeln mit Intervallen wurden gel\u00f6st:         insert rule x y tcp sport { 3478-3497, 16384-16387 } counter accept\n<li class=\"l\"> Die JSON-API wurde verbessert, in der nun Unterst\u00fctzung f\u00fcr Ausdr\u00fccke in Set- und Map-Listen verf\u00fcgbar ist.\n<li class=\"l\"> In den Erweiterungen zur Python-Bibliothek nftables wurde das Laden von Regelsets zur Verarbeitung im Pr\u00fcfmodus (&#171;-c&#187;) und die Unterst\u00fctzung f\u00fcr externe Variablen\u5b9a\u4e49 hinzugef\u00fcgt.\n<li class=\"l\"> In den Elementen der Set-Listen ist das Hinzuf\u00fcgen von Kommentaren erlaubt.\n<li class=\"l\"> Bei der Byte-Ratelimitierung ist die Angabe eines Nullwerts erlaubt worden.    <\/ul>\n<p>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58378\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables). \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106246","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables).\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-paketnogo-filtra-nftables-1-0-6\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables).\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-paketnogo-filtra-nftables-1-0-6\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-23T13:36:42+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-23T13:36:42+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Release des paketbasierten Filters nftables 1.0.6 | ProHoster","description":"Die Version des Paketfilters nftables 1.0.6 wurde ver\u00f6ffentlicht, die die Schnittstellen zur Filterung von Paketen f\u00fcr IPv4, IPv6, ARP und Netzwerkbr\u00fccken vereinheitlicht (zielt auf den Ersatz von iptables, ip6tables, arptables und ebtables ab).","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-paketnogo-filtra-nftables-1-0-6","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables).","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-paketnogo-filtra-nftables-1-0-6","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-12-23T13:36:42+00:00","article:modified_time":"2022-12-23T13:36:42+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/106246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=106246"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/106246\/revisions"}],"predecessor-version":[{"id":164207,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/106246\/revisions\/164207"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=106246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=106246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=106246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}