Release of Packet Filter Iptables 1.8.12

After a year and a half of development, the release of the classic toolkit for managing the packet filter iptables 1.8.12 has been published. Recently, its development has focused on components for maintaining backward compatibility — iptables-nft and ebtables-nft, which provide utilities with the same command line syntax as iptables and ebtables but translate the received rules into nftables bytecode. The original set of iptables programs, including ip6tables, arptables, and ebtables, was deprecated in 2018 and has already been replaced with nftables in most distributions.

In the new version:

  • The iptables-nft utility implements support for atomic addition and replacement of rules in a single transaction. *filter -A FORWARD -m comment --comment "new rule being replaced" -R FORWARD 1 -m comment --comment "new replacing rule" COMMIT
  • The xtables-monitor utility has added support for recognizing operations that delete base chains (INPUT, FORWARD, OUTPUT) and outputting the command "iptables -X chain_name" in such cases.
  • Translation to nftables format has been provided for rules with the protocol '-p sctp' without explicitly specifying the module '-m sctp', as is done for TCP and UDP (it is sufficient to specify '-p tcp' or '-p udp', and '-m tcp' or '-m udp' will be applied automatically).
  • Support for ICPM packets info-request and info-reply has been added.
  • Errors in the iptables-translate and ip6tables-translate utilities, used for converting rules to nftables, have been corrected.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster