{"id":76505,"date":"2020-04-02T19:42:00","date_gmt":"2020-04-02T17:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-4"},"modified":"2020-04-02T19:42:00","modified_gmt":"2020-04-02T17:42:00","slug":"vypusk-paketnogo-filtra-nftables-0-9-4","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-4","title":{"rendered":"Rilascio del filtro a pacchetto nftables 0.9.4","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/marc.info\/?l=netfilter&#038;m=158575148505527&#038;w=2\">Pubblicato<\/a><\/noindex> rilascio del filtro dei pacchetti <noindex><a rel=\"nofollow\" href=\"https:\/\/netfilter.org\/projects\/nftables\/\">nftables 0.9.4<\/a><\/noindex>, in fase di sviluppo come sostituto di iptables, ip6tables, arptables ed ebtables grazie all'unificazione delle interfacce di filtraggio dei pacchetti per IPv4, IPv6, ARP e bridge di rete. Il pacchetto nftables include componenti del filtro dei pacchetti che operano nello spazio utente, mentre a livello del kernel l'operazione \u00e8 gestita dal sottosistema nf_tables, incluso nel kernel Linux a partire dalla versione 3.13. Le modifiche necessarie al rilascio di nftables 0.9.4 sono incluse nella futura branch del kernel <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52632\">Linux 5.6<\/a><\/noindex>.<\/p>\n<p>A livello di kernel, viene fornito solo un'interfaccia generale, indipendente dal protocollo specifico, che offre funzioni di base per l'estrazione dei dati dai pacchetti, l'esecuzione delle operazioni sui dati e la gestione del flusso. Le regole di filtraggio e i gestori specifici per i protocolli sono compilati in bytecode nello spazio utente, dopodich\u00e9 questo bytecode viene caricato nel kernel tramite l'interfaccia Netlink ed eseguito nel kernel in una speciale macchina virtuale, simile ai BPF (Berkeley Packet Filters). Questo approccio consente di ridurre notevolmente la dimensione del codice di filtraggio che opera a livello di kernel e di spostare tutte le funzioni di parsing delle regole e la logica di lavoro con i protocolli nello spazio utente.<\/p>\n<p>Novit\u00e0 principali:\n<\/p>\n<ul>\n<li class=\"l\"> Supporto per le gamme nelle concatenazioni (concatenazione, specifici legami di indirizzi e porte che semplificano l'abbinamento). Ad esempio, per il set \u00abwhitelist\u00bb, i cui elementi sono una concatenazione, specificare il flag \u00abinterval\u00bb indicher\u00e0 che il set pu\u00f2 includere gamme nella concatenazione (per la concatenazione \u00abipv4_addr . ipv4_addr . inet_service\u00bb in precedenza era possibile elencare corrispondenze esatte come \u00ab192.168.10.35 . 192.68.11.123 . 80\u00bb, mentre ora \u00e8 possibile specificare gruppi di indirizzi \u00ab192.168.10.35-192.168.10.40 . 192.68.11.123-192.168.11.125 . 80\u00bb):\n<p>    table ip foo {<br \/>\n           set whitelist {<br \/>\n                   type ipv4_addr . ipv4_addr . inet_service<br \/>\n                   flags interval<br \/>\n                   elements = { 192.168.10.35-192.168.10.40 . 192.68.11.123-192.168.11.125 . 80 }<br \/>\n           }<\/p>\n<p>           chain bar {<br \/>\n                   type filter hook prerouting priority filter; policy drop;<br \/>\n                   ip saddr . ip daddr . tcp dport @whitelist accept<br \/>\n           }<br \/>\n    }<\/p>\n<li class=\"l\"> Nei set e nelle mappe \u00e8 stata garantita la possibilit\u00e0 di utilizzare la direttiva \u00abtypeof\u00bb, che determina il formato dell'elemento durante l'abbinamento.<br \/>\n Ad esempio:<\/p>\n<p>     table ip foo {<br \/>\n            set whitelist {<br \/>\n                    typeof ip saddr<br \/>\n                    elements = { 192.168.10.35, 192.168.10.101, 192.168.10.135 }<br \/>\n            }<\/p>\n<p>            chain bar {<br \/>\n                    type filter hook prerouting priority filter; policy drop;<br \/>\n                    ip daddr @whitelist accept<br \/>\n            }<br \/>\n     }<\/p>\n<p>     table ip foo {<br \/>\n            map addr2mark {<br \/>\n                typeof ip saddr : meta mark<br \/>\n                elements = { 192.168.10.35 : 0x00000001, 192.168.10.135 : 0x00000002 }<br \/>\n            }<br \/>\n     }<\/p>\n<li class=\"l\"> \u00c8 stata aggiunta la possibilit\u00e0 di utilizzare concatenazioni nei NAT bindings, permettendo di specificare indirizzi e porte nella definizione delle trasformazioni NAT basate su map-list o set nominati:\n<p>      nft add rule ip nat pre dnat ip addr . port to ip saddr map { 1.1.1.1 : 2.2.2.2 . 30 }<\/p>\n<p>      nft add map ip nat destinations { type ipv4_addr . inet_service : ipv4_addr . inet_service \\; }<br \/>\n      nft add rule ip nat pre dnat ip addr . port to ip saddr . tcp dport map @destinations<\/p>\n<li class=\"l\"> Supporto per l'accelerazione hardware con l'assegnazione di alcune operazioni di filtraggio alle schede di rete. L'accelerazione si attiva tramite l'utility ethtool (\"ethtool -K eth0 hw-tc-offload on\"), dopodich\u00e9 viene abilitata in nftables per la catena principale utilizzando il flag \"offload\". Con il kernel Linux 5.6 \u00e8 supportata l'accelerazione hardware per il matching dei campi dell'intestazione e il controllo dell'interfaccia in ingresso in combinazione con la ricezione, il drop, la duplicazione (dup) e il reindirizzamento (fwd) dei pacchetti. Nel seguente esempio, le operazioni di drop dei pacchetti provenienti dall'indirizzo 192.168.30.20 vengono eseguite a livello della scheda di rete, senza passare i pacchetti al kernel:\n<p>     # cat file.nft<br \/>\n     table netdev x {<br \/>\n            catena y {<br \/>\n                type filter hook ingress device eth0 priority 10; flags offload;<br \/>\n                ip saddr 192.168.30.20 drop<br \/>\n            }<br \/>\n     }<br \/>\n     # nft -f file.nft<\/p>\n<li class=\"l\"> Migliorata la segnalazione della posizione dell'errore nelle regole.\n<p>     # nft delete rule ip y z handle 7<br \/>\n     Errore: Impossibile elaborare la regola: Nessun file o directory di questo tipo<br \/>\n     delete rule ip y z handle 7<br \/>\n                    ^<\/p>\n<p>     # nft delete rule ip x x handle 7<br \/>\n     Errore: Impossibile elaborare la regola: Nessun file o directory di questo tipo<br \/>\n     delete rule ip x x handle 7<br \/>\n                               ^<\/p>\n<p>     # nft delete table twst<br \/>\n     Errore: File o directory non trovati; intendevi la tabella 'test' nella famiglia ip?<br \/>\n     delete table twst<br \/>\n                  ^^^^<\/p>\n<p>Nel primo esempio si mostra che la tabella 'y' \u00e8 assente nel sistema, nel secondo che il gestore '7' \u00e8 assente, e nel terzo che viene fornito un suggerimento su un errore di battitura durante la digitazione del nome della tabella.<\/p>\n<li class=\"l\"> Aggiunto supporto per il controllo dell'interfaccia slave tramite l'indicazione 'meta sdif' o 'meta sdifname':\n<p>        \u2026 meta sdifname vrf1 \u2026<\/p>\n<li class=\"l\"> \u00c8 stata aggiunta la funzionalit\u00e0 di operazione di spostamento a destra o a sinistra. Ad esempio, per spostare un'etichetta di pacchetto esistente a sinistra di 1 bit e impostare il bit meno significativo a 1:\n<p>        \u2026 meta mark set meta mark lshift 1 or 0x1 \u2026<\/p>\n<li class=\"l\"> Implementata l'opzione '-V' per visualizzare informazioni dettagliate sulla versione.\n<p>     # nft -V<br \/>\n       nftables v0.9.4 (Jive at Five)<br \/>\n          cli:          readline<br \/>\n          json:         s\u00ec<br \/>\n          minigmp:      no<br \/>\n          libxtables:   s\u00ec<\/p>\n<li class=\"l\"> Le opzioni della riga di comando devono ora essere specificate prima dei comandi. Ad esempio, \u00e8 necessario indicare &#171;nft -a list ruleset&#187;, mentre l'esecuzione di &#171;nft list ruleset -a&#187; generer\u00e0 un errore.\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52656\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.4, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043c\u0435\u043d\u044b iptables, ip6table, arptables \u0438 ebtables \u0437\u0430 \u0441\u0447\u0451\u0442 \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432. \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-76505","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.4, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043c\u0435\u043d\u044b iptables, ip6table, arptables \u0438 ebtables \u0437\u0430 \u0441\u0447\u0451\u0442 \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432. \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-4\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.4 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.4, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043c\u0435\u043d\u044b iptables, ip6table, arptables \u0438 ebtables \u0437\u0430 \u0441\u0447\u0451\u0442 \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432. \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-4\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-02T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-02T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Rilascio del filtro pacchetti nftables 0.9.4 | ProHoster","description":"\u00c8 stata pubblicata la versione 0.9.4 del filtro pacchetti nftables, che si sta sviluppando come sostituto di iptables, ip6tables, arptables ed ebtables, grazie all'unificazione delle interfacce di filtraggio dei pacchetti per IPv4, IPv6, ARP e ponti di rete. Il pacchetto nftables include componenti del filtro pacchetti che operano nello spazio utente, mentre a livello di kernel il funzionamento \u00e8 garantito dal sottosistema nf_tables, parte integrante del kernel Linux.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-4","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.4 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.4, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043c\u0435\u043d\u044b iptables, ip6table, arptables \u0438 ebtables \u0437\u0430 \u0441\u0447\u0451\u0442 \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432. \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-4","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-02T17:42:00+00:00","article:modified_time":"2020-04-02T17:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"76505","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:35:41","updated":"2022-10-07 02:56:47"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/76505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=76505"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/76505\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=76505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=76505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=76505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}