{"id":106246,"date":"2022-12-23T15:36:42","date_gmt":"2022-12-23T13:36:42","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-1-0-6"},"modified":"2022-12-23T15:36:42","modified_gmt":"2022-12-23T13:36:42","slug":"vypusk-paketnogo-filtra-nftables-1-0-6","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-1-0-6","title":{"rendered":"L\u00ebshimi i filtrit t\u00eb paketave nftables 1.0.6","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cbsht\u00eb publikuar l\u00ebshimi i filtrit t\u00eb paketave nftables 1.0.6, q\u00eb unifikon nd\u00ebrfaqet e filtrimit t\u00eb paketave p\u00ebr IPv4, IPv6, ARP dhe urat rrjet\u00ebs (n\u00eb synimin p\u00ebr t\u00eb z\u00ebvend\u00ebsuar iptables, ip6tables, arptables dhe ebtables). Paketa nftables p\u00ebrfshin komponent\u00eb t\u00eb filtrit t\u00eb paketave q\u00eb punojn\u00eb n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, nd\u00ebrsa n\u00eb nivelin e b\u00ebrtham\u00ebs funksionin e siguron n\u00ebn-sistemi nf_tables, i pranish\u00ebm n\u00eb b\u00ebrtham\u00ebn Linux q\u00eb prej l\u00ebshimit 3.13. N\u00eb nivelin e b\u00ebrtham\u00ebs ofrohet vet\u00ebm nj\u00eb nd\u00ebrfaqe e p\u00ebrgjithshme, e pavarur nga protokolli konkret dhe q\u00eb siguron funksione thelb\u00ebsore p\u00ebr nxjerrjen e t\u00eb dh\u00ebnave nga paketat, realizimin e operacioneve me t\u00eb dh\u00ebnat dhe menaxhimin e rrjedhave.    <\/p>\n<p>Rregullat e filtrimit dhe trajtuesit specifik p\u00ebr protokollet kompilohet n\u00eb kodin e bytes n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, pas s\u00eb cil\u00ebs ky kod bytes ngarkohet n\u00eb b\u00ebrtham\u00eb p\u00ebrmes nd\u00ebrfaqes Netlink dhe ekzekutohet n\u00eb b\u00ebrtham\u00eb n\u00eb nj\u00eb mjedis t\u00eb ve\u00e7ant\u00eb. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/vps\/abuzoustojchivye-vps\/\"   title=\"makin\u00ebn virtuale\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4332\">makin\u00ebn virtuale<\/a>, i ngjan Berkley Packet Filters (BPF). Qashtu, kjo qasje lejon t\u00eb reduktohet ndjesh\u00ebm madh\u00ebsia e kodit t\u00eb filtrimit q\u00eb funksionon n\u00eb nivelin e b\u00ebrtham\u00ebs dhe t\u00eb nxirren t\u00eb gjitha funksionet e analiz\u00ebs s\u00eb rregullave dhe logjik\u00ebs s\u00eb pun\u00ebs me protokollet n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit.    <\/p>\n<p>Ndryshimet kryesore:  <\/p>\n<ul>\n<li class=\"l\"> N\u00eb optimizuesin e rregullave, i aktivizuara kur specifikohet opsioni &#171;-o\/&#8212;optimize&#187;, \u00ebsht\u00eb vendosur paketa automatike e rregullave p\u00ebrmes bashkimit t\u00eb tyre dhe transformimit n\u00eb lista map dhe set. P\u00ebr shembull, rregullat         # cat ruleset.nft       table ip x {              chain y {                     type filter hook input priority filter; policy drop;                     meta iifname eth1 ip saddr 1.1.1.1 ip daddr 2.2.2.3 accept                     meta iifname eth1 ip saddr 1.1.1.2 ip daddr 2.2.2.4 accept                     meta iifname eth1 ip saddr 1.1.1.2 ip daddr 2.2.3.0\/24 accept                     meta iifname eth1 ip saddr 1.1.1.2 ip daddr 2.2.4.0-2.2.4.10   accept                     meta iifname eth2 ip saddr 1.1.1.3 ip daddr 2.2.2.5 accept              }       }    pas ekzekutimit t\u00eb &#171;nft -o -c -f ruleset.nft&#187; do t\u00eb transformohen si m\u00eb posht\u00eb:         ruleset.nft:4:17-74:                 meta iifname eth1 ip saddr 1.1.1.1 ip   daddr 2.2.2.3 accept       ruleset.nft:5:17-74:                 meta iifname eth1 ip saddr 1.1.1.2 ip   daddr 2.2.2.4 accept       ruleset.nft:6:17-77:                 meta iifname eth1 ip saddr 1.1.1.2 ip   daddr 2.2.3.0\/24 accept       ruleset.nft:7:17-83:                 meta iifname eth1 ip saddr 1.1.1.2 ip   daddr 2.2.4.0-2.2.4.10 accept       ruleset.nft:8:17-74:                 meta iifname eth2 ip saddr 1.1.1.3 ip   daddr 2.2.2.5 accept       n\u00eb:               iifname . ip saddr . ip daddr { eth1 . 1.1.1.1 . 2.2.2.3, eth1 .   1.1.1.2 . 2.2.2.4, eth1 . 1.1.1.2 . 2.2.3.0\/24, eth1 . 1.1.1.2 .   2.2.4.0-2.2.4.10, eth2 . 1.1.1.3 . 2.2.2.5 } accept\n<li class=\"l\"> Optimizuesi gjithashtu mund t\u00eb transformoj\u00eb n\u00eb nj\u00eb form\u00eb m\u00eb kompakte rregullat q\u00eb tashm\u00eb p\u00ebrdorin lista t\u00eb thjeshta set, p\u00ebr shembuj rregullat:         # cat ruleset.nft       table ip filter {              chain input {                     type filter hook input priority filter; policy drop;                     iifname &#171;lo&#187; accept                     ct state established,related accept comment &#171;N\u00eb trafik q\u00eb ne e origjinojm\u00eb, besojm\u00eb&#187;                     iifname &#171;enp0s31f6&#187; ip saddr { 209.115.181.102,   216.197.228.230 } ip daddr 10.0.0.149 udp sport 123 udp dport 32768-65535 accept                     iifname &#171;enp0s31f6&#187; ip saddr { 64.59.144.17, 64.59.150.133 }   ip daddr 10.0.0.149 udp sport 53 udp dport 32768-65535 accept             }       }    pas ekzekutimit t\u00eb &#171;nft -o -c -f ruleset.nft&#187; do t\u00eb paketohen si m\u00eb posht\u00eb:         ruleset.nft:6:22-149:                      iifname &#171;enp0s31f6&#187; ip saddr {   209.115.181.102, 216.197.228.230 } ip daddr 10.0.0.149 udp sport 123 udp dport   32768-65535 accept       ruleset.nft:7:22-143:                      iifname &#171;enp0s31f6&#187; ip saddr {   64.59.144.17, 64.59.150.133 } ip daddr 10.0.0.149 udp sport 53 udp dport   32768-65535 accept       n\u00eb:                  iifname . ip saddr . ip daddr . udp sport . udp dport {   enp0s31f6 . 209.115.181.102 . 10.0.0.149 . 123 . 32768-65535, enp0s31f6 .   216.197.228.230 . 10.0.0.149 . 123 . 32768-65535, enp0s31f6 . 64.59.144.17 .   10.0.0.149 . 53 . 32768-65535, enp0s31f6 . 64.59.150.133 . 10.0.0.149 . 53 .   32768-65535 } accept\n<li class=\"l\"> \u00cbsht\u00eb zgjidhur problemi me gjenerimin e kodit t\u00eb bajt\u00ebve p\u00ebr bashkimin e intervaleve, ku aplikohen tipe me renditje t\u00eb ndryshme bajt\u00ebsh, p\u00ebr shembull IPv4 (renditje n\u00eb rrjet t\u00eb bajt\u00ebve) dhe meta mark (renditje sistemike e bajt\u00ebve).        table ip x {             map w {                   typeof ip saddr . meta mark : verdict                   flags interval                   counter                   elements = {                           127.0.0.1-127.0.0.4 . 0x123434-0xb00122 : accept,                           192.168.0.10-192.168.1.20 . 0x0000aa00-0x0000aaff :   accept,                   }            }            chain k {                   type filter hook input priority filter; policy drop;                   ip saddr . meta mark vmap @w            }      }\n<li class=\"l\"> \u00cbsht\u00eb realizuar mapimi i protokolleve t\u00eb rralla kur p\u00ebrdoren shprehjet raw, p\u00ebr shembull:         meta l4proto 91 @th,400,16 0x0 accept\n<li class=\"l\"> Jan\u00eb zgjidhur problemet me futjen e rregullave me intervuale:         insert rule x y tcp sport { 3478-3497, 16384-16387 } counter accept\n<li class=\"l\"> API JSON \u00ebsht\u00eb p\u00ebrmir\u00ebsuar, duke p\u00ebrfshir\u00eb mb\u00ebshtetje p\u00ebr shprehjet n\u00eb set- dhe map-lista.\n<li class=\"l\"> N\u00eb shtesat p\u00ebr bibliotek\u00ebn python-e nftables \u00ebsht\u00eb e mundur t\u00eb ngarkohet grupe rregullash p\u00ebr p\u00ebrpunim n\u00eb modin e kontrollit (&#171;-c&#187;) dhe \u00ebsht\u00eb shtuar mb\u00ebshtetje p\u00ebr p\u00ebrcaktimin e jasht\u00ebm t\u00eb variablave.\n<li class=\"l\"> N\u00eb element\u00ebt e listave set \u00ebsht\u00eb lejuar shtimi i komenteve.\n<li class=\"l\"> N\u00eb byte ratelimit \u00ebsht\u00eb lejuar specifikimi i vler\u00ebs zero.    <\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58378\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables). \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106246","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables). \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-1-0-6\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables). \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-1-0-6\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-23T13:36:42+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-23T13:36:42+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47L\u00ebshimi i filtrit t\u00eb paketave nftables 1.0.6 | ProHoster","description":"\u00cbsht\u00eb publikuar l\u00ebshimi i filtrit t\u00eb paketave nftables 1.0.6, q\u00eb unifikon nd\u00ebrfaqet e filtrimit t\u00eb paketave p\u00ebr IPv4, IPv6, ARP dhe urat rrjet\u00ebs (n\u00eb synimin p\u00ebr t\u00eb z\u00ebvend\u00ebsuar iptables, ip6tables, arptables dhe ebtables). Paketa nftables p\u00ebrfshin komponent\u00eb t\u00eb filtrit t\u00eb paketave q\u00eb punojn\u00eb n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, nd\u00ebrsa n\u00eb nivelin e b\u00ebrtham\u00ebs funksionin e siguron n\u00ebn-sistemi nf_tables, i pranish\u00ebm n\u00eb b\u00ebrtham\u00ebn Linux q\u00eb prej l\u00ebshimit","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-1-0-6","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 1.0.6, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432 (\u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 \u0437\u0430\u043c\u0435\u043d\u0443 iptables, ip6table, arptables \u0438 ebtables). \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u044b\u043f\u0443\u0441\u043a\u0430","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-1-0-6","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-12-23T13:36:42+00:00","article:modified_time":"2022-12-23T13:36:42+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/106246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=106246"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/106246\/revisions"}],"predecessor-version":[{"id":164207,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/106246\/revisions\/164207"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=106246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=106246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=106246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}