{"id":38916,"date":"2019-10-31T22:26:43","date_gmt":"2019-10-31T19:26:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-debian-11-predlagaetsya-po-umolchaniyu-zadejstvovat-nftables-i-firewalld\/"},"modified":"2019-10-31T22:26:43","modified_gmt":"2019-10-31T19:26:43","slug":"v-debian-11-predlagaetsya-po-umolchaniyu-zadejstvovat-nftables-i-firewalld","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/v-debian-11-predlagaetsya-po-umolchaniyu-zadejstvovat-nftables-i-firewalld","title":{"rendered":"\u00cen Debian 11, se sugereaz\u0103 activarea nftables \u0219i firewalld implicit.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Arturo Borrero, dezvoltator Debian, membru al echipei centrale a proiectului Netfilter, \u0219i care \u00eentre\u021bine \u00een Debian pachetele asociate cu nftables, iptables \u0219i netfilter, <noindex><a rel=\"nofollow\" href=\"https:\/\/ral-arturo.org\/2019\/10\/14\/debian-netfilter.html\">a propus<\/a><\/noindex> urmeaz\u0103 s\u0103 traduc\u0103 urm\u0103toarea lansare semnificativ\u0103 a distribu\u021biei Debian 11 pentru a utiliza nftables ca implicit. \u00cen cazul aprob\u0103rii propunerii, pachetele cu iptables vor fi clasificate ca op\u021biuni op\u021bionale, neincluse \u00een livrarea de baz\u0103.<\/p>\n<p>Filtrul de pachete Nftables este remarcabil prin unificarea interfe\u021belor de filtrare a pachetelor pentru IPv4, IPv6, ARP \u0219i pun\u021bi de re\u021bea. Nftables ofer\u0103 la nivel de nucleu o interfa\u021b\u0103 comun\u0103, independent\u0103 de protocolul specific, \u0219i furnizeaz\u0103 func\u021bii de baz\u0103 pentru extragerea datelor din pachete, executarea opera\u021biunilor cu datele \u0219i gestionarea fluxului. Logica de filtrare \u0219i manipulatoarele specifice protocoalelor sunt compilate \u00een bytecode \u00een spa\u021biul utilizatorului, dup\u0103 care acest bytecode este \u00eenc\u0103rcat \u00een nucleu prin intermediul interfe\u021bei Netlink \u0219i executat \u00eentr-o ma\u0219in\u0103 virtual\u0103 special\u0103, asem\u0103n\u0103toare BPF (Berkeley Packet Filters). <\/p>\n<p>\u00cen mod implicit, \u00een Debian 11 se propune de asemenea activarea firewall-ului dinamic firewalld, conceput ca un strat deasupra nftables. Firewalld ruleaz\u0103 ca un proces \u00een fundal, permi\u021b\u00e2nd modificarea dinamic\u0103 a regulilor de filtrare a pachetelor prin DBus, f\u0103r\u0103 a necesita re\u00eenc\u0103rcarea regulilor de filtrare a pachetelor \u0219i f\u0103r\u0103 a \u00eentrerupe conexiunile stabilite. Pentru gestionarea firewall-ului se utilizeaz\u0103 utilitarul firewall-cmd, care la crearea regulilor se bazeaz\u0103 nu pe <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/lir\/ipv4\/\"   title=\"adreselor IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"805\">adreselor IP<\/a>, interfe\u021belor de re\u021bea \u0219i numerelor de porturi, dar \u0219i de denumirile serviciilor (de exemplu, pentru a permite accesul la SSH trebuie s\u0103 executa\u021bi &#171;firewall-cmd &#8212;add &#8212;service=ssh&#187;, iar pentru a \u00eenchide SSH &#8211; &#171;firewall-cmd &#8212;remove &#8212;service=ssh&#187;).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51671\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0410\u0440\u0442\u0443\u0440\u043e \u0411\u043e\u0440\u0440\u0435\u0440\u043e (Arturo Borrero), \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a Debian, \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0432 Coreteam \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Netfilter \u0438 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0439 \u0432 Debian \u043f\u0430\u043a\u0435\u0442\u044b, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 nftables, iptables \u0438 netfilter, \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0438\u043b \u043f\u0435\u0440\u0435\u0432\u0435\u0441\u0442\u0438 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0439 \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Debian 11 \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 nftables \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e. \u0412 \u0441\u043b\u0443\u0447\u0430\u0435 \u0443\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u044b \u0441 iptables \u0431\u0443\u0434\u0443\u0442 \u043f\u0435\u0440\u0435\u0432\u0435\u0434\u0435\u043d\u044b \u0432 \u0440\u0430\u0437\u0440\u044f\u0434 \u043d\u0435\u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u043e\u043f\u0446\u0438\u0439, \u043d\u0435 \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0445 \u0432 \u0431\u0430\u0437\u043e\u0432\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443. \u041f\u0430\u043a\u0435\u0442\u043d\u044b\u0439 \u0444\u0438\u043b\u044c\u0442\u0440 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38916","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0410\u0440\u0442\u0443\u0440\u043e \u0411\u043e\u0440\u0440\u0435\u0440\u043e (Arturo Borrero), \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a Debian, \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0432 Coreteam \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Netfilter \u0438 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0439 \u0432 Debian \u043f\u0430\u043a\u0435\u0442\u044b, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 nftables, iptables \u0438 netfilter,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/v-debian-11-predlagaetsya-po-umolchaniyu-zadejstvovat-nftables-i-firewalld\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Debian 11 \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c nftables \u0438 firewalld | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0410\u0440\u0442\u0443\u0440\u043e \u0411\u043e\u0440\u0440\u0435\u0440\u043e (Arturo Borrero), \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a Debian, \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0432 Coreteam \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Netfilter \u0438 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0439 \u0432 Debian \u043f\u0430\u043a\u0435\u0442\u044b, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 nftables, iptables \u0438 netfilter,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/v-debian-11-predlagaetsya-po-umolchaniyu-zadejstvovat-nftables-i-firewalld\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:26:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:26:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00cen Debian 11 se propune \u00een mod implicit utilizarea nftables \u0219i firewalld | ProHoster","description":"Arturo Borrero, dezvoltator Debian, membru al echipei centrale a proiectului Netfilter, \u0219i care \u00eentre\u021bine \u00een Debian pachetele asociate cu nftables, iptables \u0219i netfilter,","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/v-debian-11-predlagaetsya-po-umolchaniyu-zadejstvovat-nftables-i-firewalld","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Debian 11 \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c nftables \u0438 firewalld | ProHoster","og:description":"\u0410\u0440\u0442\u0443\u0440\u043e \u0411\u043e\u0440\u0440\u0435\u0440\u043e (Arturo Borrero), \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a Debian, \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0432 Coreteam \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Netfilter \u0438 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u0439 \u0432 Debian \u043f\u0430\u043a\u0435\u0442\u044b, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 nftables, iptables \u0438 netfilter,","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/v-debian-11-predlagaetsya-po-umolchaniyu-zadejstvovat-nftables-i-firewalld","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:26:43+00:00","article:modified_time":"2019-10-31T19:26:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38916","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 20:44:57","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:00:27","updated":"2026-02-08 20:44:57","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/38916","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=38916"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/38916\/revisions"}],"predecessor-version":[{"id":157996,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/38916\/revisions\/157996"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=38916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=38916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=38916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}