In Debian 11, nftables and firewalld are suggested to be enabled by default

Arturo Borrero, a Debian developer and member of the Coreteam for the Netfilter project, maintains the packages related to nftables, iptables, and netfilter in Debian. proposed to translate the next significant release of the Debian 11 distribution to use nftables by default. If the proposal is approved, the iptables packages will be classified as optional and not included in the base installation.

The Nftables packet filter is notable for unifying the filtering interfaces for IPv4, IPv6, ARP, and network bridges. Nftables provides a kernel-level interface that is independent of specific protocols and offers basic functions for packet data extraction, data operations, and flow control. The filtering logic and protocol-specific handlers are compiled into bytecode in user space, which is then loaded into the kernel via the Netlink interface and executed in a special virtual machine resembling BPF (Berkeley Packet Filters).

By default, Debian 11 also proposes to use the dynamic firewall firewalld, which is implemented as a wrapper on top of nftables. Firewalld runs as a background process, allowing dynamic modifications of packet filter rules via DBus, without the need to reload the packet filter rules and without interrupting established connections. The firewall is managed using the firewall-cmd utility, which creates rules based not on (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community.network interfaces and port numbers, but on service names (for example, to allow SSH access you need to run ‘firewall-cmd --add --service=ssh’, to close SSH – ‘firewall-cmd --remove --service=ssh’).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster