{"id":37278,"date":"2019-10-31T22:16:45","date_gmt":"2019-10-31T19:16:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/vypusk-paketnogo-filtra-nftables-0-9-2\/"},"modified":"2019-10-31T22:16:45","modified_gmt":"2019-10-31T19:16:45","slug":"vypusk-paketnogo-filtra-nftables-0-9-2","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-2","title":{"rendered":"L\u00ebshimi i filtrit n\u00eb grup nftables 0.9.2","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/marc.info\/?l=netfilter&#038;m=156621590113089&#038;w=2\">U zhvillua<\/a><\/noindex> l\u00ebshimi i filtrit t\u00eb paketave <noindex><a rel=\"nofollow\" href=\"https:\/\/netfilter.org\/projects\/nftables\/\">nftables 0.9.2<\/a><\/noindex>, duke u zhvilluar si nj\u00eb z\u00ebvend\u00ebsim p\u00ebr iptables, ip6tables, arptables dhe ebtables p\u00ebrmes unifikimit t\u00eb interfeseve t\u00eb filtrimit t\u00eb paketave p\u00ebr IPv4, IPv6, ARP dhe urat e rrjetit. Paketa nftables p\u00ebrmban komponent\u00eb t\u00eb filtrit t\u00eb paketave q\u00eb punojn\u00eb n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, nd\u00ebrsa n\u00eb nivelin e kernelit \u00ebsht\u00eb e pun\u00ebsuar n\u00ebn-sistemi nf_tables, i cili \u00ebsht\u00eb pjes\u00eb e kernelit t\u00eb Linux q\u00eb nga l\u00ebshimi 3.13. Ndryshimet e nevojshme p\u00ebr funksionimin e l\u00ebshimit nftables 0.9.2 p\u00ebrfshijn\u00eb integrimin n\u00eb kernelin e Linux 5.3.<\/p>\n<p>N\u00eb nivelin e kernelit ofrohet vet\u00ebm nj\u00eb nd\u00ebrfaqe e p\u00ebrgjithshme, e pavarur nga protokolli specifik dhe q\u00eb siguron funksionet baz\u00eb p\u00ebr nxjerrjen e t\u00eb dh\u00ebnave nga paketat, kryerjen e operacioneve mbi t\u00eb dh\u00ebnat dhe menaxhimin e rrjedh\u00ebs. Vet\u00eb logjika e filtrimit dhe p\u00ebrpunuesit specifik\u00eb p\u00ebr protokollet kompilohen n\u00eb bytecode n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, m\u00eb pas ky bytecode ngarkohet n\u00eb kernel me an\u00eb t\u00eb nd\u00ebrfaqes Netlink dhe ekzekutohet n\u00eb nj\u00eb makin\u00eb virtuale t\u00eb posa\u00e7me, t\u00eb ngjashme me BPF (Berkeley Packet Filters). Kjo qasje mund\u00ebson ulje t\u00eb ndjeshme t\u00eb madh\u00ebsis\u00eb s\u00eb kodit t\u00eb filtrimit q\u00eb ekzekutohet n\u00eb nivelin e kernelit dhe zhvendos t\u00eb gjitha funksionet e analizimit t\u00eb rregullave dhe logjik\u00ebn e pun\u00ebs me protokollet n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit.<\/p>\n<p>Novitetet kryesore:<\/p>\n<ul>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb verifikuar numrin e portit nga header-i i paket\u00ebs n\u00eb nivelin e transportit pavar\u00ebsisht nga lloji i protokollit t\u00eb nivelit 4:\n<p>   shto rregull x y ip protokolli { tcp, udp } th dport 53<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr rikthimin e koh\u00ebs s\u00eb jet\u00ebs s\u00eb nj\u00eb grupi element\u00ebsh:\n<p>   shto element ip x y { 1.1.1.1 timeout 30s skadon 15s }<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb verifikuar opsione t\u00eb ve\u00e7anta (lsrr, rr, ssrr dhe ra) nga paketat IPv4:\n<p>   shto rregull x y ip opsioni rr ekziston heq<\/p>\n<p>P\u00ebr opsionet e rrug\u00ebs, \u00ebsht\u00eb e mundur t\u00eb kontrolloni fushat type, ptr, length dhe addr:<\/p>\n<p>   shto rregull x y ip opsioni rr type 1 heq<\/p>\n<li class=\"l\"> N\u00eb shprehje tani \u00ebsht\u00eb e lejueshme t\u00eb especificohen prefikse rrjeti dhe intervale adresash:\n<p>   iifname ens3 snat to 10.0.0.0\/28<br \/>\n   iifname ens3 snat to 10.0.0.1-10.0.0.15<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr p\u00ebrdorimin e variablave n\u00eb p\u00ebrcaktimet e zinxhir\u00ebve:\n<p>    p\u00ebrcakto default_policy = prano<br \/>\n    shto zinxhir ip foo bar { tipi filtrues kllapa hyr\u00ebse prioriteti filtrues; politika $default_policy }<\/p>\n<li class=\"l\"> Tani mund t\u00eb tregohet prioriteti i zinxhirit si n\u00eb form\u00eb numerike ashtu edhe n\u00eb form\u00eb simbolike:\n<p>    p\u00ebrcakto prio = filtrues<br \/>\n    p\u00ebrcakto prionum = 10<br \/>\n    p\u00ebrcakto prioffset = \u00abfilter \u2014 150\u00bb<\/p>\n<p>    shto tavolin\u00eb ip foo<br \/>\n    shto zinxhir ip foo bar { tipi filtrues kllapa hyr\u00ebse prioriteti $prio; }<br \/>\n    shto zinxhir ip foo ber { tipi filtrues kllapa hyr\u00ebse prioriteti $prionum; }<br \/>\n    shto zinxhir ip foo bor { tipi filtrues kllapa hyr\u00ebse prioriteti $prioffset; }<\/p>\n<li class=\"l\"> \u00cbsht\u00eb e implementuar mb\u00ebshtetje p\u00ebr modulun synproxy. P\u00ebr shembull, p\u00ebr t\u00eb mbrojtur portin TCP 8888 n\u00ebn mbrojtjen e synproxy, mund t\u00eb p\u00ebrdoren rregulla t\u00eb k\u00ebtij tipi:\n<p>    tabela ip x {<br \/>\n            zinxhir y {<br \/>\n                    type filter hook prerouting priority raw; policy accept;<br \/>\n                    tcp dport 8888 tcp flags syn notrack<br \/>\n            }<\/p>\n<p>            zinxhiri z {<br \/>\n                    type filter hook forward priority filter; policy accept;<br \/>\n                    tcp dport 8888 ct gjendja e pavlefshme, e pa ndjekur synproxy mss 1460 \\<br \/>\n                       wscale 7 timestamp sack-perm ct gjendja e pavlefshme heq<br \/>\n            }<br \/>\n    }<\/p>\n<li class=\"l\"> P\u00ebr t\u00eb p\u00ebrcaktuar n\u00eb tabel\u00ebn conntrack lidhur me lidhjen aktuale, pritjet e lidhjeve t\u00eb tjera t\u00eb pritshme q\u00eb zbatohen n\u00eb protokollet dhe skenar\u00ebt q\u00eb k\u00ebrkojn\u00eb vendosjen e disa lidhjeve, tani mund t\u00eb p\u00ebrcaktohen politika p\u00ebrmes grupeve t\u00eb zakonshme t\u00eb rregullave. P\u00ebr shembull, p\u00ebr t\u00eb caktuar lidhjet e pritshme pas lidhjes n\u00eb portin TCP 8888 p\u00ebr lidhjet e m\u00ebpasshme n\u00eb portin 5432, mund t\u00eb jepen rregulla t\u00eb m\u00ebposhtme:\n<p>        tabela x {<br \/>\n                ct pritja myexpect {<br \/>\n                        protokolli tcp<br \/>\n                        dport 5432<br \/>\n                        timeout 1h<br \/>\n                        size 12<br \/>\n                        l3proto ip<br \/>\n                }<\/p>\n<p>                zinxhir hyr\u00ebs {<br \/>\n                        tipi filtrues kllapa hyr\u00ebse prioriteti 0;<br \/>\n                        ct gjendja e re tcp dport 8888 ct pritja set myexpect<br \/>\n                        ct gjendja e ngritur, e lidhur num\u00ebro pranoni<br \/>\n                }<br \/>\n        }<\/p>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51312\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.2, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043c\u0435\u043d\u044b iptables, ip6table, arptables \u0438 ebtables \u0437\u0430 \u0441\u0447\u0451\u0442 \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432. \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37278","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-2\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.2 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-2\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:16:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:16:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47L\u00ebshimi i filtrit t\u00eb paketave nftables 0.9.2 | ProHoster","description":"U l\u00ebshua filtri i paketave","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-2","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.2 | ProHoster","og:description":"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-2","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:16:45+00:00","article:modified_time":"2019-10-31T19:16:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37278","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:04:39","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:30:00","updated":"2026-01-23 17:04:39","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/37278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=37278"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/37278\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=37278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=37278"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=37278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}