{"id":53598,"date":"2019-12-05T00:00:00","date_gmt":"2019-12-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vypusk-paketnogo-filtra-nftables-0-9-3"},"modified":"2020-02-18T14:01:31","modified_gmt":"2020-02-18T11:01:31","slug":"vypusk-paketnogo-filtra-nftables-0-9-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-3","title":{"rendered":"L\u00ebshimi i filtrit paketor nftables 0.9.3","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/marc.info\/?l=linux-netdev&#038;m=157532146517289&#038;w=2\">Publikuar<\/a><\/noindex> l\u00ebshimi i filtrit t\u00eb paketave <noindex><a rel=\"nofollow\" href=\"https:\/\/netfilter.org\/projects\/nftables\/\">nftables 0.9.3<\/a><\/noindex>, q\u00eb po zhvillohet si nj\u00eb z\u00ebvend\u00ebsim p\u00ebr iptables, ip6tables, arptables dhe ebtables p\u00ebrmes unifikimit t\u00eb nd\u00ebrfaqeve t\u00eb filtrimit t\u00eb paketave p\u00ebr IPv4, IPv6, ARP dhe urat rrjet\u00ebsore. Paketa nftables p\u00ebrfshin komponimet e filtrit t\u00eb paketave q\u00eb funksionojn\u00eb n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, nd\u00ebrsa n\u00eb nivelin e b\u00ebrtham\u00ebs, puna sigurohet nga n\u00ebn-sistemi nf_tables, i cili \u00ebsht\u00eb pjes\u00eb e b\u00ebrtham\u00ebs Linux q\u00eb nga versione 3.13. Ndryshimet e nevojshme p\u00ebr funksionimin e versionit nftables 0.9.3 jan\u00eb p\u00ebrfshir\u00eb n\u00eb deg\u00ebn e ardhshme t\u00eb b\u00ebrtham\u00ebs Linux 5.5.<\/p>\n<p>N\u00eb nivelin e b\u00ebrtham\u00ebs, ofrohet vet\u00ebm nj\u00eb nd\u00ebrfaqe e p\u00ebrgjithshme, q\u00eb nuk varet nga nj\u00eb protokoll i caktuar dhe ofron funksione bazike p\u00ebr nxjerrjen e t\u00eb dh\u00ebnave nga paketat, kryerjen e operacioneve me t\u00eb dh\u00ebna dhe menaxhimin e rrjedh\u00ebs. Logjika e filtrimit dhe trajtuesit specifik\u00eb p\u00ebr protokollet kompilohet n\u00eb kod byte n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, pas s\u00eb cil\u00ebs ky kod byte ngarkohet n\u00eb b\u00ebrtham\u00eb p\u00ebrmes nd\u00ebrfaqes Netlink dhe ekzekutohet n\u00eb nj\u00eb makin\u00eb virtuale speciale, e ngjashme me BPF (Berkeley Packet Filters). Ky qasje lejon t\u00eb reduktohet ndjesh\u00ebm madh\u00ebsia e kodit t\u00eb filtrimit, q\u00eb funksionon n\u00eb nivelin e b\u00ebrtham\u00ebs, dhe t\u00eb nxirren t\u00eb gjitha funksionet e analiz\u00ebs s\u00eb rregullave dhe logjik\u00ebs s\u00eb pun\u00ebs me protokollet n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit.<\/p>\n<p>T\u00eb rejat kryesore:<\/p>\n<ul>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr p\u00ebrputhjen e paketave sipas koh\u00ebs. Mund t\u00eb p\u00ebrcaktohen si intervale kohore dhe datash n\u00eb t\u00eb cilat do t\u00eb veproj\u00eb rregulli, ashtu si dhe t\u00eb vendoset veprimi n\u00eb dit\u00eb t\u00eb ve\u00e7anta t\u00eb jav\u00ebs. Po ashtu \u00ebsht\u00eb shtuar nj\u00eb opsion i ri \u00ab-T\u00bb p\u00ebr t\u00eb shfaqur koh\u00ebn epokale n\u00eb sekonda.\n<p>     meta time \u00ab2019-12-24 16:00\u00bb \u2014 \u00ab2020-01-02 7:00\u00bb<br \/>\n     meta hour \u00ab17:00\u00bb \u2014 \u00ab19:00\u00bb<br \/>\n     meta day \u00abFri\u00bb<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr rikthimin dhe ruajtjen e etiketave SELinux (secmark).\n<p>     ct secmark set meta secmark<br \/>\n     meta secmark set ct secmark<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr listat e hart\u00ebs synproxy, q\u00eb lejojn\u00eb p\u00ebrcaktimin e m\u00eb shum\u00eb se nj\u00eb rregulli n\u00eb backend.\n<p>    table ip foo {<br \/>\n            synproxy https-synproxy {<br \/>\n                    mss 1460<br \/>\n                    wscale 7<br \/>\n                    timestamp sack-perm<br \/>\n            }<\/p>\n<p>            synproxy other-synproxy {<br \/>\n                    mss 1460<br \/>\n                    wscale 5<br \/>\n            }<\/p>\n<p>            chain pre {<br \/>\n                    tipi filtri lidhni paralajm\u00ebrimin p\u00ebrpar\u00ebsi t\u00eb pap\u00ebrpunuar; politika prano;<br \/>\n                    tcp dport 8888 tcp flags syn notrack<br \/>\n            }<\/p>\n<p>            chain bar {<br \/>\n                    tipi filtri lidhni p\u00ebrpara p\u00ebrpar\u00ebsi filtri; politika prano;<br \/>\n                    ct state invalid, untracked synproxy name ip saddr map { 192.168.1.0\/24 : \u00abhttps-synproxy\u00bb, 192.168.2.0\/24 : \u00abother-synproxy\u00bb }<br \/>\n            }<br \/>\n     }<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb fshir\u00eb dinamikisht element\u00ebt e grupeve set nga rregullat e p\u00ebrpunimit t\u00eb pakove.\n<p>     nft add rule \u2026 delete @set5 { ip6 saddr . ip6 daddr }<\/p>\n<li class=\"l\"> Mb\u00ebshtetje p\u00ebr p\u00ebrshtatjen e VLAN sipas identifikuesit dhe protokollit, t\u00eb p\u00ebrcaktuar n\u00eb metadata e nd\u00ebrfaqes s\u00eb ur\u00ebs rrjetit;\n<p>        meta ibrpvid 100<br \/>\n        meta ibrvproto vlan<\/p>\n<li class=\"l\"> Opcioni \u00ab-t\u00bb (\u00ab--terse\u00bb) p\u00ebr p\u00ebrjashtimin e elementeve t\u00eb set-grupeve gjat\u00eb shfaqjes s\u00eb rregullave. Gjat\u00eb ekzekutimit t\u00eb \u00abnft -t list ruleset\u00bb do t\u00eb shfaqet:\n<p>    tavolin\u00eb ip x {<br \/>\n        set y {<br \/>\n                type ipv4_addr<br \/>\n        }<br \/>\n    }<\/p>\n<p>Dhe me \u00abnft list ruleset\u00bb<\/p>\n<p>    tavolin\u00eb ip x {<br \/>\n        set y {<br \/>\n                type ipv4_addr<br \/>\n                elements = { 192.168.10.2, 192.168.20.1,<br \/>\n                             192.168.4.4, 192.168.2.34 }<br \/>\n        }<br \/>\n    }<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb treguar m\u00eb shum\u00eb se nj\u00eb pajisje n\u00eb zinxhir\u00ebt netdev (funksionon vet\u00ebm me b\u00ebrtham\u00ebn 5.5) p\u00ebr t\u00eb integruar rregulla tipike filtrimi.\n<p>     add table netdev x<br \/>\n     add chain netdev x y {<br \/>\n        type filter hook ingress devices = { eth0, eth1 } priority 0;<br \/>\n     }<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb shtuar p\u00ebrshkrime p\u00ebr llojet e t\u00eb dh\u00ebnave.\n<p>    # nft describe ipv4_addr<br \/>\n    datatype ipv4_addr (IPv4 address) (basetype integer), 32 bits<\/p>\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb nd\u00ebrtuar nd\u00ebrfaqen CLI me bibliotek\u00ebn linenoise n\u00eb vend t\u00eb libreadline.\n<p>     .\/configure --with-cli=linenoise<\/p>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51980\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.3, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043c\u0435\u043d\u044b iptables, ip6table, arptables \u0438 ebtables \u0437\u0430 \u0441\u0447\u0451\u0442 \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f IPv4, IPv6, ARP \u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043c\u043e\u0441\u0442\u043e\u0432. \u0412 \u043f\u0430\u043a\u0435\u0442 nftables \u0432\u0445\u043e\u0434\u044f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u0430\u043a \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 nf_tables, \u0432\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53598","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.3 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:31+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Lan\u00e7imi i filtrit t\u00eb paketave nftables 0.9.3 | ProHoster","description":"\u00cbsht\u00eb publikuar nj\u00eb num\u00ebr i paket\u00ebs s\u00eb filtrit","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables 0.9.3 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/vypusk-paketnogo-filtra-nftables-0-9-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-04T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:31+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53598","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 08:02:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:22:49","updated":"2026-01-24 08:02:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=53598"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53598\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=53598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=53598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=53598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}