Debian 11 ืžืฆื™ืข nftables ื•ื—ื•ืžืช ืืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ

Arturo Borrero, ืžืคืชื— Debian ืฉื”ื•ื ื—ืœืง ืž-Netfilter Project Coreteam ื•ืžืชื—ื–ืง ื—ื‘ื™ืœื•ืช ื”ืงืฉื•ืจื•ืช ืœ-nftables, iptables ื•-netfilter ื‘ื“ื‘ื™ืืŸ, ืžื•ืฆืข ื”ืขื‘ืจ ืืช ื”ืžื”ื“ื•ืจื” ื”ื’ื“ื•ืœื” ื”ื‘ืื” ืฉืœ ื“ื‘ื™ืืŸ 11 ืœืฉื™ืžื•ืฉ ื‘-nftables ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืื ื”ื”ืฆืขื” ืชืื•ืฉืจ, ื—ื‘ื™ืœื•ืช ืขื iptables ื™ื™ื“ืจืฉื• ืœืงื˜ื’ื•ืจื™ื™ืช ื”ืืคืฉืจื•ื™ื•ืช ื”ืื•ืคืฆื™ื•ื ืœื™ื•ืช ืฉืื™ื ืŸ ื›ืœื•ืœื•ืช ื‘ื—ื‘ื™ืœื” ื”ื‘ืกื™ืกื™ืช.

ืžืกื ืŸ ืžื ื•ืช Nftables ื‘ื•ืœื˜ ื‘ืื™ื—ื•ื“ ืฉืœื• ืฉืœ ืžืžืฉืงื™ ืกื™ื ื•ืŸ ืžื ื•ืช ืขื‘ื•ืจ IPv4, IPv6, ARP ื•ื’ืฉืจื™ ืจืฉืช. Nftables ืžืกืคืงืช ืจืง ืžืžืฉืง ื’ื ืจื™, ื‘ืœืชื™ ืชืœื•ื™ ื‘ืคืจื•ื˜ื•ืงื•ืœ ื‘ืจืžืช ื”ืงืจื ืœ, ื”ืžืกืคืง ืคื•ื ืงืฆื™ื•ืช ื‘ืกื™ืกื™ื•ืช ืœื—ื™ืœื•ืฅ ื ืชื•ื ื™ื ืžื—ื‘ื™ืœื•ืช, ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื ืชื•ื ื™ื ื•ื‘ืงืจืช ื–ืจื™ืžื”. ืœื•ื’ื™ืงื™ืช ื”ืกื™ื ื•ืŸ ืขืฆืžื” ื•ื”ืžื˜ืคืœื™ื ื”ืกืคืฆื™ืคื™ื™ื ืœืคืจื•ื˜ื•ืงื•ืœ ืžื•ืจื›ื‘ื™ื ืœืชื•ืš bytecode ื‘ืžืจื—ื‘ ื”ืžืฉืชืžืฉ, ื•ืœืื—ืจ ืžื›ืŸ ืงื•ื“ ื‘ื™ืช ื–ื” ื ื˜ืขืŸ ืœืชื•ืš ื”ืœื™ื‘ื” ื‘ืืžืฆืขื•ืช ืžืžืฉืง Netlink ื•ืžื‘ื•ืฆืข ื‘ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืžื™ื•ื—ื“ืช ื”ืžื–ื›ื™ืจื” ืืช BPF (Berkeley Packet Filters).

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื“ื‘ื™ืืŸ 11 ืžืฆื™ืขื” ื’ื ื—ื•ืžืช ื”ืืฉ ื”ื“ื™ื ืžื™ืช ืฉืœ ื—ื•ืžืช ื”ืืฉ, ื”ืžืขื•ืฆื‘ืช ื›ืขื˜ื™ืคื” ืขืœ ื’ื‘ื™ nftables. Firewalld ืคื•ืขืœ ื›ืชื”ืœื™ืš ืจืงืข ื”ืžืืคืฉืจ ืœืš ืœืฉื ื•ืช ื‘ืื•ืคืŸ ื“ื™ื ืžื™ ื›ืœืœื™ ืกื™ื ื•ืŸ ืžื ื•ืช ื‘ืืžืฆืขื•ืช DBus ืžื‘ืœื™ ืœื˜ืขื•ืŸ ืžื—ื“ืฉ ืืช ื›ืœืœื™ ืžืกื ืŸ ื”ืžื ื•ืช ืื• ืœืฉื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ืฉื ื•ืฆืจื•. ืœื ื™ื”ื•ืœ ื—ื•ืžืช ื”ืืฉ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช Firewall-cmd, ืืฉืจ, ื‘ืขืช ื™ืฆื™ืจืช ื›ืœืœื™ื, ืžื‘ื•ืกืก ืœื ืขืœ ื›ืชื•ื‘ื•ืช IP, ืžืžืฉืงื™ ืจืฉืช ื•ืžืกืคืจื™ ื™ืฆื™ืื•ืช, ืืœื ืขืœ ืฉืžื•ืช ื”ืฉื™ืจื•ืชื™ื (ืœื“ื•ื’ืžื”, ื›ื“ื™ ืœืคืชื•ื— ื’ื™ืฉื” ืœ-SSH ืืชื” ืฆืจื™ืš ื”ืคืขืœ ืืช "firewall-cmd โ€”add โ€”service= ssh", ื›ื“ื™ ืœืกื’ื•ืจ ืืช SSH - "firewall-cmd -remove -service=ssh").

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”