ืื•ื‘ื•ื ื˜ื• 20.10 ืžืชื›ื ื ืช ืœืขื‘ื•ืจ ืž-iptables ืœ-nftables

ื”ื‘ื ืคื“ื•ืจื” ะธ ื“ื‘ื™ืืŸ ืžืคืชื—ื™ ืื•ื‘ื•ื ื˜ื• ืฉื•ืงืœื™ื ืขื‘ื•ืจ ืœืžืกื ืŸ ืžื ื•ืช ื‘ืจื™ืจืช ืžื—ื“ืœ nftables.
ื›ื“ื™ ืœืฉืžื•ืจ ืขืœ ืชืื™ืžื•ืช ืœืื—ื•ืจ, ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ื—ื‘ื™ืœื” iptables-nft, ื”ืžืกืคืง ื›ืœื™ ืขื–ืจ ืขื ืื•ืชื• ืชื—ื‘ื™ืจ ืฉื•ืจืช ืคืงื•ื“ื” ื›ืžื• iptables, ืืš ืžืชืจื’ื ืืช ื”ื›ืœืœื™ื ื”ืžืชืงื‘ืœื™ื ืœ-nf_tables bytecode. ื”ืฉื™ื ื•ื™ ืžืชื•ื›ื ืŸ ืœื”ื™ื›ืœืœ ื‘ืžื”ื“ื•ืจืช ื”ืกืชื™ื• ืฉืœ ืื•ื‘ื•ื ื˜ื• 20.10.

ื–ื”ื• ื”ื ื™ืกื™ื•ืŸ ื”ืฉื ื™ ืœื”ืขื‘ื™ืจ ืืช ืื•ื‘ื•ื ื˜ื• ืœ-nftables. ื”ื ื™ืกื™ื•ืŸ ื”ืจืืฉื•ืŸ ื ืขืฉื” ื‘ืฉื ื” ืฉืขื‘ืจื”, ืืš ื ื“ื—ื” ืขืงื‘ ืื™ ื”ืชืืžื” ืขื ืขืจื›ืช ื”ื›ืœื™ื Lxd. ืขื›ืฉื™ื• ื‘-LXD ื›ื‘ืจ ะธะผะตะตั‚ัั ืชืžื™ื›ื” ืžืงื•ืจื™ืช ืขื‘ื•ืจ nftables ื•ื”ื™ื ื™ื›ื•ืœื” ืœืขื‘ื•ื“ ืขื ื”ืงืฆื” ื”ืื—ื•ืจื™ ื”ื—ื“ืฉ ืฉืœ ืกื™ื ื•ืŸ ืžื ื•ืช. ืœืžืฉืชืžืฉื™ื ืฉืื™ืŸ ืœื”ื ืžืกืคื™ืง ืฉื›ื‘ืช ืชืื™ืžื•ืช, ื ึธื˜ื•ึผืฉื ื”ื™ื›ื•ืœืช ืœื”ืชืงื™ืŸ ื›ืœื™ ืขื–ืจ ืงืœืืกื™ื™ื iptables, ip6tables, arptables ื•-ebtables ืขื ื”-backend ื”ื™ืฉืŸ.

ื–ื›ื•ืจ ื–ืืช ื‘ืžืกื ืŸ ืžื ื•ืช nftables ืžืžืฉืงื™ ืกื™ื ื•ืŸ ืžื ื•ืช ืขื‘ื•ืจ IPv4, IPv6, ARP ื•ื’ืฉืจื™ ืจืฉืช ืื•ื—ื“ื•. ื—ื‘ื™ืœืช nftables ื›ื•ืœืœืช ืจื›ื™ื‘ื™ ืžืกื ืŸ ืžื ื•ืช ื”ืคื•ืขืœื™ื ื‘ื—ืœืœ ื”ืžืฉืชืžืฉ, ื‘ืขื•ื“ ืฉื”ืขื‘ื•ื“ื” ื‘ืจืžืช ื”ืœื™ื‘ื” ืžืกื•ืคืงืช ืขืœ ื™ื“ื™ ืชืช-ื”ืžืขืจื›ืช nf_tables, ืฉื”ื™ื™ืชื” ื—ืœืง ืžืœื™ื‘ืช ืœื™ื ื•ืงืก ืžืื– ื’ืจืกื” 3.13. ืจืžืช ื”ืงืจื ืœ ืžืกืคืงืช ืจืง ืžืžืฉืง ื’ื ืจื™ ื‘ืœืชื™ ืชืœื•ื™ ื‘ืคืจื•ื˜ื•ืงื•ืœ ื”ืžืกืคืง ืคื•ื ืงืฆื™ื•ืช ื‘ืกื™ืกื™ื•ืช ืœื—ื™ืœื•ืฅ ื ืชื•ื ื™ื ืžืžื ื•ืช, ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื ืชื•ื ื™ื ื•ื‘ืงืจืช ื–ืจื™ืžื”.

ื›ืœืœื™ ื”ืกื™ื ื•ืŸ ืขืฆืžื ื•ื”ืžื˜ืคืœื™ื ื”ืกืคืฆื™ืคื™ื™ื ืœืคืจื•ื˜ื•ืงื•ืœ ืžื•ืจื›ื‘ื™ื ืœืชื•ืš bytecode ืฉืœ ืžืจื—ื‘ ื”ืžืฉืชืžืฉ, ื•ืœืื—ืจ ืžื›ืŸ ืงื•ื“ ื‘ื™ืช ื–ื” ื ื˜ืขืŸ ืœืชื•ืš ื”ืœื™ื‘ื” ื‘ืืžืฆืขื•ืช ืžืžืฉืง Netlink ื•ืžื‘ื•ืฆืข ื‘ืงืจื ืœ ื‘ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืžื™ื•ื—ื“ืช ื”ื“ื•ืžื” ืœ-BPF (Berkeley Packet Filters). ื’ื™ืฉื” ื–ื• ืžืืคืฉืจืช ืœื”ืงื˜ื™ืŸ ืžืฉืžืขื•ืชื™ืช ืืช ื’ื•ื“ืœ ืงื•ื“ ื”ืกื™ื ื•ืŸ ื”ืคื•ืขืœ ื‘ืจืžืช ื”ืงืจื ืœ ื•ืœื”ืขื‘ื™ืจ ืืช ื›ืœ ื”ืคื•ื ืงืฆื™ื•ืช ืฉืœ ื—ื•ืงื™ ื”ื ื™ืชื•ื— ื•ื”ื”ื™ื’ื™ื•ืŸ ืฉืœ ืขื‘ื•ื“ื” ืขื ืคืจื•ื˜ื•ืงื•ืœื™ื ืœืžืจื—ื‘ ื”ืžืฉืชืžืฉ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”