The release of the iptables 1.8.11 packet filter.

After a year of development, the release of the classic toolkit for managing the iptables packet filter, version 1.8.11, has been published. Recently, its development has focused on components aimed at maintaining backward compatibility — iptables-nft and ebtables-nft, which provide utilities with the same command line syntax as iptables and ebtables but translate the resulting rules into the nftables bytecode. The original set of iptables programs, including ip6tables, arptables, and ebtables, was demoted to obsolete in 2018 and has mostly been replaced by nftables in most distributions.

In the new version:

  • A new utility, arptables-translate, has been added to convert arptables rules into a configuration format for use with nftables.
  • Support for the '--change-counters', '--replace', and '--list-rules' commands has been added to the ebtables-nft utility. It is now possible to specify counters for rules using the syntax '-c N,M'. The ability to reset specific rules has also been included.
  • The iptables-translate utility has been enhanced with support for TPROXY targets and the xt_socket extension for socket matching. The definition of protocol names has been unified with iptables.
  • The iptables utility now includes implicit extension searching for dccp and ipcomp protocols to achieve behavior consistent with iptables-save.
  • Calls to getprotobynumber() have been removed from the iptables-save utility to improve performance when processing large sets of rules.
  • The configure script has been updated to allow the disabling of builds with libnfnetlink.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster