{"id":92493,"date":"2020-08-27T19:42:43","date_gmt":"2020-08-27T17:42:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables"},"modified":"2020-08-27T19:42:43","modified_gmt":"2020-08-27T17:42:43","slug":"v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","title":{"rendered":"Dans Ubuntu 20.10, il est pr\u00e9vu de passer d'iptables \u00e0 nftables","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Suite \u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52828\">Fedora<\/a><\/noindex> et <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51671\">Debian<\/a><\/noindex> les d\u00e9veloppeurs d'Ubuntu <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.ubuntu.com\/archives\/ubuntu-devel\/2020-August\/041142.html\">envisagent la possibilit\u00e9<\/a><\/noindex> le passage \u00e0 l'utilisation par d\u00e9faut du filtre de paquets <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53106\">nftables<\/a><\/noindex>.<br \/>\nPour garantir la r\u00e9trocompatibilit\u00e9, il est propos\u00e9 d'utiliser le paquet <noindex><a rel=\"nofollow\" href=\"http:\/\/manpages.ubuntu.com\/manpages\/focal\/man8\/iptables-nft.8.html\">iptables-nft<\/a><\/noindex>, qui fournit des utilitaires avec la m\u00eame syntaxe de ligne de commande que celle d'iptables, mais traduisant les r\u00e8gles re\u00e7ues en bytecode nf_tables. Ce changement est pr\u00e9vu pour \u00eatre inclus dans la sortie automnale d'Ubuntu 20.10.<\/p>\n<p>C'est la deuxi\u00e8me tentative de transition d'Ubuntu vers nftables. La premi\u00e8re tentative a \u00e9t\u00e9 faite l'ann\u00e9e derni\u00e8re, mais a \u00e9t\u00e9 rejet\u00e9e en raison d'incompatibilit\u00e9s avec les outils <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52679\">LXD<\/a><\/noindex>. Maintenant, dans LXD, il y a d\u00e9j\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/lxc\/lxd\/issues\/6223\">un support pour XWayland;<\/a><\/noindex> un support int\u00e9gr\u00e9 pour nftables et il peut fonctionner avec le nouveau backend pour le filtrage des paquets. Pour les utilisateurs qui ne se contentent pas d'une couche de compatibilit\u00e9, <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.debian.org\/nftables#Reverting_to_legacy_xtables\">est rest\u00e9e<\/a><\/noindex> il est possible d'installer les utilitaires classiques iptables, ip6tables, arptables et ebtables avec l'ancien backend.<\/p>\n<p>Rappelons que dans le filtre de paquets <noindex><a rel=\"nofollow\" href=\"https:\/\/netfilter.org\/projects\/nftables\/\">nftables<\/a><\/noindex> les interfaces de filtrage des paquets pour IPv4, IPv6, ARP et les ponts r\u00e9seau sont unifi\u00e9es. Dans le paquet nftables, des composants de filtrage des paquets fonctionnent en espace utilisateur, tandis qu'au niveau du noyau, le syst\u00e8me nf_tables, int\u00e9gr\u00e9 au noyau Linux depuis la version 3.13, g\u00e8re le travail. Au niveau du noyau, seul une interface g\u00e9n\u00e9rale est fournie, ind\u00e9pendante des protocoles sp\u00e9cifiques et offrant des fonctionnalit\u00e9s de base pour l'extraction de donn\u00e9es des paquets, la r\u00e9alisation d'op\u00e9rations sur les donn\u00e9es et la gestion du flux. <\/p>\n<p>Directement, les r\u00e8gles de filtrage et les gestionnaires sp\u00e9cifiques aux protocoles sont compil\u00e9s en bytecode en espace utilisateur, qui est ensuite charg\u00e9 dans le noyau via l'interface Netlink et ex\u00e9cut\u00e9 dans le noyau dans une machine virtuelle sp\u00e9ciale, semblable \u00e0 BPF (Berkeley Packet Filters). Cette approche permet de r\u00e9duire consid\u00e9rablement la taille du code de filtrage fonctionnant au niveau du noyau et d'externaliser toutes les fonctions d'analyse des r\u00e8gles et de logique de travail avec les protocoles en espace utilisateur.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53608\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438 Debian \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 Ubuntu \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0430 \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables. \u0414\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0439 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0430\u043a\u0435\u0442 iptables-nft, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0439 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0441 \u0442\u0435\u043c \u0436\u0435 \u0441\u0438\u043d\u0442\u0430\u043a\u0441\u0438\u0441\u043e\u043c \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438, \u043a\u0430\u043a \u0438 \u0432 iptables, \u043d\u043e \u0442\u0440\u0430\u043d\u0441\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u043d\u044b\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0432 \u0431\u0430\u0439\u0442\u043a\u043e\u0434 nf_tables. \u0418\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u043e\u0441\u0435\u043d\u043d\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 Ubuntu 20.10. \u042d\u0442\u043e \u0432\u0442\u043e\u0440\u0430\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-92493","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Ubuntu 20.10 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0441 iptables \u043d\u0430 nftables | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-27T17:42:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-27T17:42:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dans Ubuntu 20.10, la transition d'iptables vers nftables est pr\u00e9vue | ProHoster","description":"Suite \u00e0 Fedora et","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Ubuntu 20.10 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0441 iptables \u043d\u0430 nftables | ProHoster","og:description":"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-27T17:42:43+00:00","article:modified_time":"2020-08-27T17:42:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"92493","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:07:40","updated":"2022-09-30 05:58:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/92493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=92493"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/92493\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=92493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=92493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=92493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}