{"id":92493,"date":"2020-08-27T19:42:43","date_gmt":"2020-08-27T17:42:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables"},"modified":"2020-08-27T19:42:43","modified_gmt":"2020-08-27T17:42:43","slug":"v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","title":{"rendered":"\u00cen Ubuntu 20.10 se planific\u0103 trecerea de la iptables la nftables","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Urm\u00e2nd <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52828\">Fedora<\/a><\/noindex> \u0219i <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51671\">Debian<\/a><\/noindex> dezvoltatorii Ubuntu <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.ubuntu.com\/archives\/ubuntu-devel\/2020-August\/041142.html\">analizeaz\u0103 posibilitatea<\/a><\/noindex> trecerii la utilizarea, implicit, a filtrului de pachete <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53106\">nftables<\/a><\/noindex>.<br \/>\nPentru a p\u0103stra compatibilitatea invers\u0103, se propune utilizarea pachetului <noindex><a rel=\"nofollow\" href=\"http:\/\/manpages.ubuntu.com\/manpages\/focal\/man8\/iptables-nft.8.html\">iptables-nft<\/a><\/noindex>, care ofer\u0103 utilitare cu aceea\u0219i sintax\u0103 de linie de comand\u0103 ca \u0219i \u00een iptables, dar transleaz\u0103 regulile primite \u00een bytecode nf_tables. Schimbarea este planificat\u0103 s\u0103 fie inclus\u0103 \u00een versiunea de toamn\u0103 a Ubuntu 20.10.<\/p>\n<p>Aceasta este a doua \u00eencercare de a trece Ubuntu la nftables. Prima \u00eencercare a avut loc anul trecut, dar a fost respins\u0103 din cauza incompatibilit\u0103\u021bii cu instrumentele <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52679\">LXD<\/a><\/noindex>. Acum, \u00een LXD exist\u0103 deja <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/lxc\/lxd\/issues\/6223\">exist\u0103<\/a><\/noindex> suport \u00eencorporat pentru nftables \u0219i poate func\u021biona cu noul backend pentru filtrarea pachetelor. Pentru utilizatorii care nu sunt mul\u021bumi\u021bi de stratul de compatibilitate, <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.debian.org\/nftables#Reverting_to_legacy_xtables\">a fost l\u0103sat\u0103<\/a><\/noindex> exist\u0103 posibilitatea instal\u0103rii utilitarelor clasice iptables, ip6tables, arptables \u0219i ebtables cu vechiul backend.<\/p>\n<p>Reamintim c\u0103 \u00een filtrul de pachete <noindex><a rel=\"nofollow\" href=\"https:\/\/netfilter.org\/projects\/nftables\/\">nftables<\/a><\/noindex> interface-urile de filtrare a pachetelor sunt unificate pentru IPv4, IPv6, ARP \u0219i pun\u021bi de re\u021bea. Pachetul nftables include componentele filtrului de pachete care func\u021bioneaz\u0103 \u00een spa\u021biul utilizatorului, \u00een timp ce la nivelul nucleului, func\u021bionarea este asigurat\u0103 de subsystemul nf_tables, inclus \u00een nucleul Linux \u00eencep\u00e2nd cu versiunea 3.13. La nivelul nucleului se ofer\u0103 doar o interfa\u021b\u0103 general\u0103, indiferent de protocolul specific, care ofer\u0103 func\u021bii de baz\u0103 pentru extragerea datelor din pachete, efectuarea de opera\u021biuni cu datele \u0219i gestionarea fluxului. <\/p>\n<p>Regulile de filtrare directe \u0219i handler-ele specifice pentru protocoale sunt compilate \u00een bytecode \u00een spa\u021biul utilizatorului, dup\u0103 care acest bytecode este \u00eenc\u0103rcat \u00een nucleu prin intermediul interfe\u021bei Netlink \u0219i executat \u00een nucleu \u00eentr-o ma\u0219in\u0103 virtual\u0103 special\u0103, asem\u0103n\u0103toare cu BPF (Berkeley Packet Filters). Aceast\u0103 abordare permite o reducere semnificativ\u0103 a dimensiunii codului de filtrare, care func\u021bioneaz\u0103 la nivel de nucleu \u0219i transfer\u0103 toate func\u021biile de analiz\u0103 a regulilor \u0219i logica de lucru cu protocoalele \u00een spa\u021biul utilizatorului.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53608\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438 Debian \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 Ubuntu \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0430 \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables. \u0414\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0439 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043f\u0430\u043a\u0435\u0442 iptables-nft, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0439 \u0443\u0442\u0438\u043b\u0438\u0442\u044b \u0441 \u0442\u0435\u043c \u0436\u0435 \u0441\u0438\u043d\u0442\u0430\u043a\u0441\u0438\u0441\u043e\u043c \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438, \u043a\u0430\u043a \u0438 \u0432 iptables, \u043d\u043e \u0442\u0440\u0430\u043d\u0441\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u043d\u044b\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0432 \u0431\u0430\u0439\u0442\u043a\u043e\u0434 nf_tables. \u0418\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u043e\u0441\u0435\u043d\u043d\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 Ubuntu 20.10. \u042d\u0442\u043e \u0432\u0442\u043e\u0440\u0430\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-92493","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Ubuntu 20.10 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0441 iptables \u043d\u0430 nftables | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-27T17:42:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-27T17:42:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00cen Ubuntu 20.10 se planific\u0103 trecerea de la iptables la nftables | ProHoster","description":"Dup\u0103 Fedora \u0219i","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Ubuntu 20.10 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0441 iptables \u043d\u0430 nftables | ProHoster","og:description":"\u0421\u043b\u0435\u0434\u043e\u043c \u0437\u0430 Fedora \u0438","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/v-ubuntu-20-10-planiruyut-perejti-s-iptables-na-nftables","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-27T17:42:43+00:00","article:modified_time":"2020-08-27T17:42:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"92493","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:07:40","updated":"2022-09-30 05:58:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/92493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=92493"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/92493\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=92493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=92493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=92493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}