{"id":92493,"date":"2020-08-27T19:42:43","date_gmt":"2020-08-27T17:42:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables"},"modified":"2020-08-27T19:42:43","modified_gmt":"2020-08-27T17:42:43","slug":"v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","title":{"rendered":"In Ubuntu 20.10 wird der \u00dcbergang von iptables zu nftables geplant.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Folgendes <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52828\">Fedora<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51671\">Debian<\/a><\/noindex> Entwickler von Ubuntu <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.ubuntu.com\/archives\/ubuntu-devel\/2020-August\/041142.html\">erw\u00e4gen die M\u00f6glichkeit<\/a><\/noindex> \u00dcbergang zur standardm\u00e4\u00dfigen Verwendung des Paketfilters <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53106\">nftables<\/a><\/noindex>.<br \/>\nUm die R\u00fcckw\u00e4rtskompatibilit\u00e4t zu gew\u00e4hrleisten, wird empfohlen, das Paket <noindex><a rel=\"nofollow\" href=\"http:\/\/manpages.ubuntu.com\/manpages\/focal\/man8\/iptables-nft.8.html\">iptables-nft<\/a><\/noindex>, das Tools mit der gleichen Befehlszeilen-Syntax wie bei iptables bereitstellt, aber die erhaltenen Regeln in Bytecode f\u00fcr nf_tables \u00fcbersetzt. Diese \u00c4nderung ist f\u00fcr die Herbstversion von Ubuntu 20.10 geplant.<\/p>\n<p>Dies ist der zweite Versuch, Ubuntu auf nftables umzustellen. Der erste Versuch wurde im letzten Jahr unternommen, wurde jedoch aufgrund von Inkompatibilit\u00e4ten mit den Tools <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52679\">LXD<\/a><\/noindex>. Jetzt gibt es in LXD bereits <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/lxc\/lxd\/issues\/6223\">gibt es<\/a><\/noindex> eingebaute Unterst\u00fctzung f\u00fcr nftables und es kann mit dem neuen Backend f\u00fcr die Paketfilterung arbeiten. F\u00fcr Benutzer, denen die Kompatibilit\u00e4tsschicht nicht ausreicht, <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.debian.org\/nftables#Reverting_to_legacy_xtables\">bleibt<\/a><\/noindex> die M\u00f6glichkeit, die klassischen Tools iptables, ip6tables, arptables und ebtables mit dem alten Backend zu installieren.<\/p>\n<p>Wir erinnern daran, dass im Paketfilter <noindex><a rel=\"nofollow\" href=\"https:\/\/netfilter.org\/projects\/nftables\/\">nftables<\/a><\/noindex> die Schnittstellen zur Paketfilterung f\u00fcr IPv4, IPv6, ARP und Netzwerkbr\u00fccken vereinheitlicht sind. Das Paket nftables umfasst Komponenten des Paketfilters, die im Benutzerspeicher arbeiten, w\u00e4hrend auf Kernel-Ebene das nf_tables-Subsystem, das seit Version 3.13 Teil des Linux-Kernels ist, die Arbeit gew\u00e4hrleistet. Auf Kernel-Ebene wird nur eine allgemeine Schnittstelle bereitgestellt, die nicht von einem bestimmten Protokoll abh\u00e4ngt und grundlegende Funktionen zum Extrahieren von Daten aus Paketen, Ausf\u00fchren von Datenoperationen und Verwalten von Datenstr\u00f6men bereitstellt. <\/p>\n<p>Die Regeln zur Filterung und protokollspezifischen Handler werden im Benutzerspeicher in Bytecode kompiliert, der dann mithilfe der Netlink-Schnittstelle in den Kernel geladen und dort in einer speziellen virtuellen Maschine, \u00e4hnlich wie BPF (Berkeley Packet Filters), ausgef\u00fchrt wird. Dieser Ansatz erm\u00f6glicht eine signifikante Reduzierung der Filtercodegr\u00f6\u00dfe, die auf Kernel-Ebene ausgef\u00fchrt wird, und verlagert alle Funktionen zur Regelverarbeitung und Protokollverarbeitung in den Benutzerspeicher.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53608\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438 Debian \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 Ubuntu \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0430 \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables. \u0414\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0439 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0430\u043a\u0435\u0442 iptables-nft, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0439 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0441 \u0442\u0435\u043c \u0436\u0435 \u0441\u0438\u043d\u0442\u0430\u043a\u0441\u0438\u0441\u043e\u043c \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438, \u043a\u0430\u043a \u0438 \u0432 iptables, \u043d\u043e \u0442\u0440\u0430\u043d\u0441\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u043d\u044b\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0432 \u0431\u0430\u0439\u0442\u043a\u043e\u0434 nf_tables. \u0418\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u043e\u0441\u0435\u043d\u043d\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 Ubuntu 20.10. \u042d\u0442\u043e \u0432\u0442\u043e\u0440\u0430\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-92493","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Ubuntu 20.10 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0441 iptables \u043d\u0430 nftables | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-27T17:42:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-27T17:42:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47In Ubuntu 20.10 plant man den Wechsel von iptables zu nftables | ProHoster","description":"Nach Fedora und","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Ubuntu 20.10 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0441 iptables \u043d\u0430 nftables | ProHoster","og:description":"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-27T17:42:43+00:00","article:modified_time":"2020-08-27T17:42:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"92493","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:07:40","updated":"2022-09-30 05:58:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/92493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=92493"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/92493\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=92493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=92493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=92493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}