{"id":53598,"date":"2019-12-05T00:00:00","date_gmt":"2019-12-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vypusk-paketnogo-filtra-nftables-0-9-3"},"modified":"2020-02-18T14:01:31","modified_gmt":"2020-02-18T11:01:31","slug":"vypusk-paketnogo-filtra-nftables-0-9-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-3","title":{"rendered":"L\u00ebshimi i filtrit t\u00eb paketave nftables 0.9.3","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/marc.info\/?l=linux-netdev&#038;m=157532146517289&#038;w=2\">Publikuar<\/a><\/noindex> l\u00ebshimi i filtrit t\u00eb paketave <noindex><a rel=\"nofollow\" href=\"https:\/\/netfilter.org\/projects\/nftables\/\">nftables 0.9.3<\/a><\/noindex>, q\u00eb po zhvillohet si z\u00ebvend\u00ebsim p\u00ebr iptables, ip6table, arptables dhe ebtables fal\u00eb unifikimit t\u00eb nd\u00ebrfaqeve t\u00eb filtrimit t\u00eb paketave p\u00ebr IPv4, IPv6, ARP dhe urat e rrjetit. Paketa nftables p\u00ebrfshin komponent\u00eb t\u00eb filtrit t\u00eb paketave q\u00eb funksionojn\u00eb n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, nd\u00ebrsa n\u00eb nivelin e kernelit funksionimin e siguron n\u00ebnsistemi nf_tables, i cili \u00ebsht\u00eb pjes\u00eb e kernelit Linux q\u00eb nga versioni 3.13. Ndryshimet e nevojshme p\u00ebr funksionimin e versionit nftables 0.9.3 jan\u00eb p\u00ebrfshir\u00eb n\u00eb deg\u00ebn e ardhshme t\u00eb kernelit Linux 5.5.<\/p>\n<p>N\u00eb nivelin e kernelit ofrohet vet\u00ebm nj\u00eb nd\u00ebrfaqe e p\u00ebrgjithshme, e pavarur nga protokolli specifik dhe q\u00eb siguron funksionet baz\u00eb p\u00ebr nxjerrjen e t\u00eb dh\u00ebnave nga paketat, kryerjen e operacioneve mbi t\u00eb dh\u00ebnat dhe menaxhimin e rrjedh\u00ebs. Vet\u00eb logjika e filtrimit dhe p\u00ebrpunuesit specifik\u00eb p\u00ebr protokollet kompilohen n\u00eb bytecode n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, m\u00eb pas ky bytecode ngarkohet n\u00eb kernel me an\u00eb t\u00eb nd\u00ebrfaqes Netlink dhe ekzekutohet n\u00eb nj\u00eb makin\u00eb virtuale t\u00eb posa\u00e7me, t\u00eb ngjashme me BPF (Berkeley Packet Filters). Kjo qasje mund\u00ebson ulje t\u00eb ndjeshme t\u00eb madh\u00ebsis\u00eb s\u00eb kodit t\u00eb filtrimit q\u00eb ekzekutohet n\u00eb nivelin e kernelit dhe zhvendos t\u00eb gjitha funksionet e analizimit t\u00eb rregullave dhe logjik\u00ebn e pun\u00ebs me protokollet n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit.<\/p>\n<p>Novitetet kryesore:<\/p>\n<ul>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr p\u00ebrputhjen e paketave sipas koh\u00ebs. Mund t\u00eb p\u00ebrcaktoni si intervalet e koh\u00ebs dhe datave n\u00eb t\u00eb cilat do t\u00eb aktivizohet rregulli, ashtu edhe t\u00eb rregulloni aktivizimin n\u00eb dit\u00eb t\u00eb ve\u00e7anta t\u00eb jav\u00ebs. Po ashtu, \u00ebsht\u00eb shtuar nj\u00eb opsion i ri &#171;-T&#187; p\u00ebr t\u00eb shfaqur koh\u00ebn epokale n\u00eb sekonda.\n<p>     meta time &#092;&#187;2019-12-24 16:00&#092;&#187; &#8212; &#092;&#187;2020-01-02 7:00&#092;&#187;<br \/>\n     meta hour &#092;&#187;17:00&#092;&#187; &#8212; &#092;&#187;19:00&#092;&#187;<br \/>\n     meta day &#092;&#187;Fri&#092;&#187;<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr rikthimin dhe ruajtjen e etiketave SELinux (secmark).\n<p>     ct secmark set meta secmark<br \/>\n     meta secmark set ct secmark<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr listat map t\u00eb synproxy, q\u00eb lejojn\u00eb p\u00ebrcaktimin e m\u00eb shum\u00eb se nj\u00eb rregulli p\u00ebr backend.\n<p>    tabela ip foo {<br \/>\n            synproxy https-synproxy {<br \/>\n                    mss 1460<br \/>\n                    wscale 7<br \/>\n                    timestamp sack-perm<br \/>\n            }<\/p>\n<p>            synproxy other-synproxy {<br \/>\n                    mss 1460<br \/>\n                    wscale 5<br \/>\n            }<\/p>\n<p>            chain pre {<br \/>\n                    type filter hook prerouting priority raw; policy accept;<br \/>\n                    tcp dport 8888 tcp flags syn notrack<br \/>\n            }<\/p>\n<p>            chain bar {<br \/>\n                    type filter hook forward priority filter; policy accept;<br \/>\n                    ct state invalid, untracked synproxy name ip saddr map { 192.168.1.0\/24 : &#171;https-synproxy&#187;, 192.168.2.0\/24 : &#171;other-synproxy&#187; }<br \/>\n            }<br \/>\n     }<\/p>\n<li class=\"l\"> Mund\u00ebsi p\u00ebr fshirjen dinamike t\u00eb elementeve t\u00eb grupeve set nga rregullat e p\u00ebrpunimit t\u00eb paketave.\n<p>     nft add rule &#8230; delete @set5 { ip6 saddr . ip6 daddr }<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr p\u00ebrputhjen e VLAN sipas identifikuesit dhe protokollit, t\u00eb p\u00ebrcaktuara n\u00eb metadatat e nd\u00ebrfaqes s\u00eb ur\u00ebs s\u00eb rrjetit;\n<p>        meta ibrpvid 100<br \/>\n        meta ibrvproto vlan<\/p>\n<li class=\"l\"> Opsioni &#171;-t&#187; (&#171;&#8212;terse&#187;) p\u00ebr p\u00ebrjashtimin e elementeve set-grupesh gjat\u00eb shfaqjes s\u00eb rregullave. Kur ekzekutoni &#171;nft -t list ruleset&#187;, do t\u00eb shfaqet:\n<p>    tabela ip x {<br \/>\n        grupi y {<br \/>\n                type ipv4_addr<br \/>\n        }<br \/>\n    }<\/p>\n<p>Dhe kur &#171;nft list ruleset&#187;<\/p>\n<p>    tabela ip x {<br \/>\n        grupi y {<br \/>\n                type ipv4_addr<br \/>\n                elements = { 192.168.10.2, 192.168.20.1,<br \/>\n                             192.168.4.4, 192.168.2.34 }<br \/>\n        }<br \/>\n    }<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb specifikuar m\u00eb shum\u00eb se nj\u00eb pajisje n\u00eb zinxhir\u00ebt netdev (funksionon vet\u00ebm me kernel 5.5) p\u00ebr t\u00eb bashkuar rregullat tipike t\u00eb filtrimit.\n<p>     add table netdev x<br \/>\n     add chain netdev x y { &#092;<br \/>\n        type filter hook ingress devices = { eth0, eth1 } priority 0;<br \/>\n     }<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb shtuar p\u00ebrshkrime t\u00eb llojeve t\u00eb t\u00eb dh\u00ebnave.\n<p>    # nft describe ipv4_addr<br \/>\n    datatype ipv4_addr (IPv4 address) (basetype integer), 32 bits<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb nd\u00ebrtuar nd\u00ebrfaqen CLI me bibliotek\u00ebn linenoise n\u00eb vend t\u00eb libreadline.\n<p>     .\\\/configure &#8212;with-cli=linenoise<\/p>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51980\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.3, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043c\u0435\u043d\u044b iptables, ip6table, arptables \u0438 ebtables \u0437\u0430 \u0441\u0447\u0451\u0442 \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432. \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53598","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.3 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:31+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Publikimi i paket\u00eb-filtrit nftables 0.9.3 | ProHoster","description":"Publikuar l\u00ebshimi i filtrit t\u00eb paketave","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.3 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/vypusk-paketnogo-filtra-nftables-0-9-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-04T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:31+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53598","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 08:02:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:22:49","updated":"2026-01-24 08:02:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=53598"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53598\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=53598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=53598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=53598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}