#iptables — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iptables, aggregated by home.social.
-
@mathew we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.
I think it will take years before nftables works with everything just like it is with ipv6.
-
@mathew we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.
I think it will take years before nftables works with everything just like it is with ipv6.
-
@mathew we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.
I think it will take years before nftables works with everything just like it is with ipv6.
-
@mathew we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.
I think it will take years before nftables works with everything just like it is with ipv6.
-
@mathew we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.
I think it will take years before nftables works with everything just like it is with ipv6.
-
Как eBPF меняет правила безопасности и наблюдаемости в Kubernetes
eBPF часто подают как кнопку «ускорить Kubernetes», но на практике всё сложнее. Он действительно помогает уйти от тяжёлых цепочек iptables, снизить задержки и получить наблюдаемость ближе к ядру Linux. Но стоит перейти от L4 к L7, включить глубокую инспекцию трафика или mTLS — и бесплатная магия заканчивается. Разбираем, где eBPF меняет правила игры, а где всё ещё приходится считать оверхед. Читать разбор
https://habr.com/ru/companies/otus/articles/1047398/
#eBPF #Kubernetes #Cilium #kubeproxy #iptables #XDP #observability #сетевые_политики #безопасность_кластера #L7фильтрация
-
Как eBPF меняет правила безопасности и наблюдаемости в Kubernetes
eBPF часто подают как кнопку «ускорить Kubernetes», но на практике всё сложнее. Он действительно помогает уйти от тяжёлых цепочек iptables, снизить задержки и получить наблюдаемость ближе к ядру Linux. Но стоит перейти от L4 к L7, включить глубокую инспекцию трафика или mTLS — и бесплатная магия заканчивается. Разбираем, где eBPF меняет правила игры, а где всё ещё приходится считать оверхед. Читать разбор
https://habr.com/ru/companies/otus/articles/1047398/
#eBPF #Kubernetes #Cilium #kubeproxy #iptables #XDP #observability #сетевые_политики #безопасность_кластера #L7фильтрация
-
Как eBPF меняет правила безопасности и наблюдаемости в Kubernetes
eBPF часто подают как кнопку «ускорить Kubernetes», но на практике всё сложнее. Он действительно помогает уйти от тяжёлых цепочек iptables, снизить задержки и получить наблюдаемость ближе к ядру Linux. Но стоит перейти от L4 к L7, включить глубокую инспекцию трафика или mTLS — и бесплатная магия заканчивается. Разбираем, где eBPF меняет правила игры, а где всё ещё приходится считать оверхед. Читать разбор
https://habr.com/ru/companies/otus/articles/1047398/
#eBPF #Kubernetes #Cilium #kubeproxy #iptables #XDP #observability #сетевые_политики #безопасность_кластера #L7фильтрация
-
Создание Android-смартфона с упором на приватность
Практический опыт ограничения приложений на Android В статье рассматривается практический опыт настройки Android‑смартфона с root‑доступом для ограничения сетевого взаимодействия приложений и управления их разрешениями. Анализ трафика, whitelist/blacklist доменов, Magisk, iptables и создание контролируемой среды на устройстве.
https://habr.com/ru/articles/1044080/
#Android #Magisk #Root #Приватность #Информационная_безопасность #Iptables #Firewall #Linux #Mobile_Security #android_security
-
Создание Android-смартфона с упором на приватность
Практический опыт ограничения приложений на Android В статье рассматривается практический опыт настройки Android‑смартфона с root‑доступом для ограничения сетевого взаимодействия приложений и управления их разрешениями. Анализ трафика, whitelist/blacklist доменов, Magisk, iptables и создание контролируемой среды на устройстве.
https://habr.com/ru/articles/1044080/
#Android #Magisk #Root #Приватность #Информационная_безопасность #Iptables #Firewall #Linux #Mobile_Security #android_security
-
Создание Android-смартфона с упором на приватность
Практический опыт ограничения приложений на Android В статье рассматривается практический опыт настройки Android‑смартфона с root‑доступом для ограничения сетевого взаимодействия приложений и управления их разрешениями. Анализ трафика, whitelist/blacklist доменов, Magisk, iptables и создание контролируемой среды на устройстве.
https://habr.com/ru/articles/1044080/
#Android #Magisk #Root #Приватность #Информационная_безопасность #Iptables #Firewall #Linux #Mobile_Security #android_security
-
Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq
Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.
-
Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq
Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.
-
Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq
Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.
-
How To Mount Remote NFS On Linux
-
Using Q-Feeds to Enhance Firewall Rules on Linux and OPNsense
-
Jugando con Kathará para emular redes TCP/IP! 🚀
Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).
Se ve muy interesante para incorporarla a las clases!
Seguramente haga algo de contenido sobre esto 🙂
+Info: https://www.kathara.org/
#uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables
-
Jugando con Kathará para emular redes TCP/IP! 🚀
Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).
Se ve muy interesante para incorporarla a las clases!
Seguramente haga algo de contenido sobre esto 🙂
+Info: https://www.kathara.org/
#uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables
-
Jugando con Kathará para emular redes TCP/IP! 🚀
Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).
Se ve muy interesante para incorporarla a las clases!
Seguramente haga algo de contenido sobre esto 🙂
+Info: https://www.kathara.org/
#uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables
-
Jugando con Kathará para emular redes TCP/IP! 🚀
Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).
Se ve muy interesante para incorporarla a las clases!
Seguramente haga algo de contenido sobre esto 🙂
+Info: https://www.kathara.org/
#uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables
-
Jugando con Kathará para emular redes TCP/IP! 🚀
Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).
Se ve muy interesante para incorporarla a las clases!
Seguramente haga algo de contenido sobre esto 🙂
+Info: https://www.kathara.org/
#uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables
-
Mastering Linux Firewalls: A Deep Dive into Netfilter and iptables
In this article, I cover how iptables works, its architecture, and practical firewall configuration techniques.
https://denizhalil.com/2025/12/31/netfilter-iptables-firewall-configuration-guide/#CyberSecurity #LinuxSecurity #iptables #Netfilter #NetworkSecurity #Firewall #InfoSec #BlueTeam #DevSecOps #securityengineering #ITSecurity #denizhalil
-
Mastering Linux Firewalls: A Deep Dive into Netfilter and iptables
In this article, I cover how iptables works, its architecture, and practical firewall configuration techniques.
https://denizhalil.com/2025/12/31/netfilter-iptables-firewall-configuration-guide/#CyberSecurity #LinuxSecurity #iptables #Netfilter #NetworkSecurity #Firewall #InfoSec #BlueTeam #DevSecOps #securityengineering #ITSecurity #denizhalil
-
Mastering Linux Firewalls: A Deep Dive into Netfilter and iptables
In this article, I cover how iptables works, its architecture, and practical firewall configuration techniques.
https://denizhalil.com/2025/12/31/netfilter-iptables-firewall-configuration-guide/#CyberSecurity #LinuxSecurity #iptables #Netfilter #NetworkSecurity #Firewall #InfoSec #BlueTeam #DevSecOps #securityengineering #ITSecurity #denizhalil
-
Mastering Linux Firewalls: A Deep Dive into Netfilter and iptables
In this article, I cover how iptables works, its architecture, and practical firewall configuration techniques.
https://denizhalil.com/2025/12/31/netfilter-iptables-firewall-configuration-guide/#CyberSecurity #LinuxSecurity #iptables #Netfilter #NetworkSecurity #Firewall #InfoSec #BlueTeam #DevSecOps #securityengineering #ITSecurity #denizhalil
-
Mastering Linux Firewalls: A Deep Dive into Netfilter and iptables
In this article, I cover how iptables works, its architecture, and practical firewall configuration techniques.
https://denizhalil.com/2025/12/31/netfilter-iptables-firewall-configuration-guide/#CyberSecurity #LinuxSecurity #iptables #Netfilter #NetworkSecurity #Firewall #InfoSec #BlueTeam #DevSecOps #securityengineering #ITSecurity #denizhalil
-
От iptables к nftables: O(n) против O(1) на практике
Если администрировать Linux-сервера достаточно долго, рано или поздно сталкиваешься с сетевой фильтрацией. Где-то нужно закрыть лишние порты, где-то ограничить доступ между сегментами сети, а где-то настроить NAT. На практике это почти всегда приводит к iptables: таблицы, цепочки, правила — и со временем конфигурация начинает напоминать археологический слой. Правила копируются, дополняются, теряют актуальность, и через пару лет уже сложно понять, почему конкретное правило вообще существует. В этой статье разберёмся, как появился nftables, чем он отличается от привычного iptables, как устроена его архитектура и как на практике использовать его для настройки firewall на Linux-сервере.
-
От iptables к nftables: O(n) против O(1) на практике
Если администрировать Linux-сервера достаточно долго, рано или поздно сталкиваешься с сетевой фильтрацией. Где-то нужно закрыть лишние порты, где-то ограничить доступ между сегментами сети, а где-то настроить NAT. На практике это почти всегда приводит к iptables: таблицы, цепочки, правила — и со временем конфигурация начинает напоминать археологический слой. Правила копируются, дополняются, теряют актуальность, и через пару лет уже сложно понять, почему конкретное правило вообще существует. В этой статье разберёмся, как появился nftables, чем он отличается от привычного iptables, как устроена его архитектура и как на практике использовать его для настройки firewall на Linux-сервере.
-
От iptables к nftables: O(n) против O(1) на практике
Если администрировать Linux-сервера достаточно долго, рано или поздно сталкиваешься с сетевой фильтрацией. Где-то нужно закрыть лишние порты, где-то ограничить доступ между сегментами сети, а где-то настроить NAT. На практике это почти всегда приводит к iptables: таблицы, цепочки, правила — и со временем конфигурация начинает напоминать археологический слой. Правила копируются, дополняются, теряют актуальность, и через пару лет уже сложно понять, почему конкретное правило вообще существует. В этой статье разберёмся, как появился nftables, чем он отличается от привычного iptables, как устроена его архитектура и как на практике использовать его для настройки firewall на Linux-сервере.
-
Три слоя защиты сервера: ipset, auto-block и CrowdSec
Ваши логи забиты попытками входа в .env , .git и wp-login.php ? Пока бот стучится в Nginx, ваш сервер уже тратит драгоценные ресурсы. Я решил перенести фильтрацию в ядро Linux и делюсь рабочим кейсом эшелонированной обороны на базе ipset и CrowdSec .
https://habr.com/ru/articles/1019778/
#WAF #ipset #iptables #CrowdSec #Битрикс #защита_сервера #безопасность #Linux #bashскрипты #информационная_безопасность
-
Три слоя защиты сервера: ipset, auto-block и CrowdSec
Ваши логи забиты попытками входа в .env , .git и wp-login.php ? Пока бот стучится в Nginx, ваш сервер уже тратит драгоценные ресурсы. Я решил перенести фильтрацию в ядро Linux и делюсь рабочим кейсом эшелонированной обороны на базе ipset и CrowdSec .
https://habr.com/ru/articles/1019778/
#WAF #ipset #iptables #CrowdSec #Битрикс #защита_сервера #безопасность #Linux #bashскрипты #информационная_безопасность
-
Три слоя защиты сервера: ipset, auto-block и CrowdSec
Ваши логи забиты попытками входа в .env , .git и wp-login.php ? Пока бот стучится в Nginx, ваш сервер уже тратит драгоценные ресурсы. Я решил перенести фильтрацию в ядро Linux и делюсь рабочим кейсом эшелонированной обороны на базе ipset и CrowdSec .
https://habr.com/ru/articles/1019778/
#WAF #ipset #iptables #CrowdSec #Битрикс #защита_сервера #безопасность #Linux #bashскрипты #информационная_безопасность
-
RE: https://mstdn.io/@d1cor/116358374535310498
¿Todavía no se enteraron que el firewall por default en Linux va a pasar a ser #nftables?
Más info de la migración y diferencias acá:
https://juncotic.com/nftables-vs-iptables-algunas-notas/
#iptables #nftables #gnu #linux #firewall #ciberseguridad #infosec #cybersecurity
-
RE: https://mstdn.io/@d1cor/116358374535310498
¿Todavía no se enteraron que el firewall por default en Linux va a pasar a ser #nftables?
Más info de la migración y diferencias acá:
https://juncotic.com/nftables-vs-iptables-algunas-notas/
#iptables #nftables #gnu #linux #firewall #ciberseguridad #infosec #cybersecurity
-
RE: https://mstdn.io/@d1cor/116358374535310498
¿Todavía no se enteraron que el firewall por default en Linux va a pasar a ser #nftables?
Más info de la migración y diferencias acá:
https://juncotic.com/nftables-vs-iptables-algunas-notas/
#iptables #nftables #gnu #linux #firewall #ciberseguridad #infosec #cybersecurity
-
RE: https://mstdn.io/@d1cor/116358374535310498
¿Todavía no se enteraron que el firewall por default en Linux va a pasar a ser #nftables?
Más info de la migración y diferencias acá:
https://juncotic.com/nftables-vs-iptables-algunas-notas/
#iptables #nftables #gnu #linux #firewall #ciberseguridad #infosec #cybersecurity
-
RE: https://mstdn.io/@d1cor/116358374535310498
¿Todavía no se enteraron que el firewall por default en Linux va a pasar a ser #nftables?
Más info de la migración y diferencias acá:
https://juncotic.com/nftables-vs-iptables-algunas-notas/
#iptables #nftables #gnu #linux #firewall #ciberseguridad #infosec #cybersecurity
-
¿Conflicto entre iptables y arptables en @archlinux?
No es un error, es una migración.
Al actualizar mi Arch me encontré con este mensaje. Lejos de ser un problema, es parte de la transición hacia #nftables como backend unificado.
🔍 ¿Qué está pasando?
El paquete moderno #iptables (1.8.11-4) ahora incluye funcionalidad ARP y Ethernet.
Ya no necesita paquetes separados como #arptables o #ebtables.
#pacman te avisa del conflicto para que no queden paquetes huérfanos.
(1/2)
-
¿Conflicto entre iptables y arptables en @archlinux?
No es un error, es una migración.
Al actualizar mi Arch me encontré con este mensaje. Lejos de ser un problema, es parte de la transición hacia #nftables como backend unificado.
🔍 ¿Qué está pasando?
El paquete moderno #iptables (1.8.11-4) ahora incluye funcionalidad ARP y Ethernet.
Ya no necesita paquetes separados como #arptables o #ebtables.
#pacman te avisa del conflicto para que no queden paquetes huérfanos.
(1/2)
-
¿Conflicto entre iptables y arptables en @archlinux?
No es un error, es una migración.
Al actualizar mi Arch me encontré con este mensaje. Lejos de ser un problema, es parte de la transición hacia #nftables como backend unificado.
🔍 ¿Qué está pasando?
El paquete moderno #iptables (1.8.11-4) ahora incluye funcionalidad ARP y Ethernet.
Ya no necesita paquetes separados como #arptables o #ebtables.
#pacman te avisa del conflicto para que no queden paquetes huérfanos.
(1/2)
-
¿Conflicto entre iptables y arptables en @archlinux?
No es un error, es una migración.
Al actualizar mi Arch me encontré con este mensaje. Lejos de ser un problema, es parte de la transición hacia #nftables como backend unificado.
🔍 ¿Qué está pasando?
El paquete moderno #iptables (1.8.11-4) ahora incluye funcionalidad ARP y Ethernet.
Ya no necesita paquetes separados como #arptables o #ebtables.
#pacman te avisa del conflicto para que no queden paquetes huérfanos.
(1/2)
-
¿Conflicto entre iptables y arptables en @archlinux?
No es un error, es una migración.
Al actualizar mi Arch me encontré con este mensaje. Lejos de ser un problema, es parte de la transición hacia #nftables como backend unificado.
🔍 ¿Qué está pasando?
El paquete moderno #iptables (1.8.11-4) ahora incluye funcionalidad ARP y Ethernet.
Ya no necesita paquetes separados como #arptables o #ebtables.
#pacman te avisa del conflicto para que no queden paquetes huérfanos.
(1/2)
-
Arch Linux aggiorna il suo stack di rete: iptables ora usa nft come backend predefinito, con benefici per gestione e modernità. #ArchLinux #iptables #nftables #Linux
-
Arch Linux aggiorna il suo stack di rete: iptables ora usa nft come backend predefinito, con benefici per gestione e modernità. #ArchLinux #iptables #nftables #Linux
-
Arch Linux aggiorna il suo stack di rete: iptables ora usa nft come backend predefinito, con benefici per gestione e modernità. #ArchLinux #iptables #nftables #Linux
-
Arch Linux aggiorna il suo stack di rete: iptables ora usa nft come backend predefinito, con benefici per gestione e modernità. #ArchLinux #iptables #nftables #Linux
-
Arch Linux aggiorna il suo stack di rete: iptables ora usa nft come backend predefinito, con benefici per gestione e modernità. #ArchLinux #iptables #nftables #Linux
-
Arch Linux now uses the "nft" backend instead of the legacy one for the iptables firewall solution!
#iptables #firewall #ArchLinux #Linux #Arch #TechNews #TechUpdates
https://officialaptivi.wordpress.com/2026/04/06/arch-linux-now-uses-the-nft-backend-for-iptables/
-
Arch Linux now uses the "nft" backend instead of the legacy one for the iptables firewall solution!
#iptables #firewall #ArchLinux #Linux #Arch #TechNews #TechUpdates
https://officialaptivi.wordpress.com/2026/04/06/arch-linux-now-uses-the-nft-backend-for-iptables/
-
Arch Linux now uses the "nft" backend instead of the legacy one for the iptables firewall solution!
#iptables #firewall #ArchLinux #Linux #Arch #TechNews #TechUpdates
https://officialaptivi.wordpress.com/2026/04/06/arch-linux-now-uses-the-nft-backend-for-iptables/
-
Arch Linux now uses the "nft" backend instead of the legacy one for the iptables firewall solution!
#iptables #firewall #ArchLinux #Linux #Arch #TechNews #TechUpdates
https://officialaptivi.wordpress.com/2026/04/06/arch-linux-now-uses-the-nft-backend-for-iptables/
-
Arch Linux now uses the "nft" backend instead of the legacy one for the iptables firewall solution!
#iptables #firewall #ArchLinux #Linux #Arch #TechNews #TechUpdates
https://officialaptivi.wordpress.com/2026/04/06/arch-linux-now-uses-the-nft-backend-for-iptables/
-
Arch Linux now uses the “nft” backend for iptables!
iptablesis a utility program for Linux that provides you a method to configure filtering rules for IP protocol, configured as different Netfilter modules. It works as a firewall to implement a different set of rules that change how the packets are treated.Arch Linux used to provide two packages for this utility, which included:
iptables-nft: This package contains theiptablesbinary with nft as the backendiptables: This package contains theiptablesbinary with the legacy backend
The Arch Linux development team has now implemented the nft backend as the default backend for the
iptablesutility, which caused theiptables-nftpackage to be considered a legacy package. Similarly, a new package, callediptables-legacy, has been created to preserve the legacy behavior.According to the official news, instructions to the system administrators have been provided to ensure that your firewall rules still work. Moreover, you’ll need to check your
/etc/iptablesdirectory for any.pacsavefiles related to the following files:/etc/iptables/iptables.rules.pacsave/etc/iptables/ip6tables.rules.pacsave
If you have any of the above files, you’ll need to restore the rules manually to ensure that they work prior to the upgrade. You can perform the full system upgrade by running
pacman -Syuas root.The developers noted that most configurations should work with no changes made once upgrades to the
#ArchLinux #iptables #Linux #news #nft #Tech #Technology #updateiptablespackage have been made. However, if you are one of the system administrators who rely on either the uncommonxtablesextension or the legacy behavior, you’ll need to uninstalliptablesand installiptables-legacy. -
Arch Linux now uses the “nft” backend for iptables!
iptablesis a utility program for Linux that provides you a method to configure filtering rules for IP protocol, configured as different Netfilter modules. It works as a firewall to implement a different set of rules that change how the packets are treated.Arch Linux used to provide two packages for this utility, which included:
iptables-nft: This package contains theiptablesbinary with nft as the backendiptables: This package contains theiptablesbinary with the legacy backend
The Arch Linux development team has now implemented the nft backend as the default backend for the
iptablesutility, which caused theiptables-nftpackage to be considered a legacy package. Similarly, a new package, callediptables-legacy, has been created to preserve the legacy behavior.According to the official news, instructions to the system administrators have been provided to ensure that your firewall rules still work. Moreover, you’ll need to check your
/etc/iptablesdirectory for any.pacsavefiles related to the following files:/etc/iptables/iptables.rules.pacsave/etc/iptables/ip6tables.rules.pacsave
If you have any of the above files, you’ll need to restore the rules manually to ensure that they work prior to the upgrade. You can perform the full system upgrade by running
pacman -Syuas root.The developers noted that most configurations should work with no changes made once upgrades to the
#ArchLinux #iptables #Linux #news #nft #Tech #Technology #updateiptablespackage have been made. However, if you are one of the system administrators who rely on either the uncommonxtablesextension or the legacy behavior, you’ll need to uninstalliptablesand installiptables-legacy. -
Arch Linux now uses the “nft” backend for iptables!
iptablesis a utility program for Linux that provides you a method to configure filtering rules for IP protocol, configured as different Netfilter modules. It works as a firewall to implement a different set of rules that change how the packets are treated.Arch Linux used to provide two packages for this utility, which included:
iptables-nft: This package contains theiptablesbinary with nft as the backendiptables: This package contains theiptablesbinary with the legacy backend
The Arch Linux development team has now implemented the nft backend as the default backend for the
iptablesutility, which caused theiptables-nftpackage to be considered a legacy package. Similarly, a new package, callediptables-legacy, has been created to preserve the legacy behavior.According to the official news, instructions to the system administrators have been provided to ensure that your firewall rules still work. Moreover, you’ll need to check your
/etc/iptablesdirectory for any.pacsavefiles related to the following files:/etc/iptables/iptables.rules.pacsave/etc/iptables/ip6tables.rules.pacsave
If you have any of the above files, you’ll need to restore the rules manually to ensure that they work prior to the upgrade. You can perform the full system upgrade by running
pacman -Syuas root.The developers noted that most configurations should work with no changes made once upgrades to the
#ArchLinux #iptables #Linux #news #nft #Tech #Technology #updateiptablespackage have been made. However, if you are one of the system administrators who rely on either the uncommonxtablesextension or the legacy behavior, you’ll need to uninstalliptablesand installiptables-legacy. -
Arch Linux now uses the “nft” backend for iptables!
iptablesis a utility program for Linux that provides you a method to configure filtering rules for IP protocol, configured as different Netfilter modules. It works as a firewall to implement a different set of rules that change how the packets are treated.Arch Linux used to provide two packages for this utility, which included:
iptables-nft: This package contains theiptablesbinary with nft as the backendiptables: This package contains theiptablesbinary with the legacy backend
The Arch Linux development team has now implemented the nft backend as the default backend for the
iptablesutility, which caused theiptables-nftpackage to be considered a legacy package. Similarly, a new package, callediptables-legacy, has been created to preserve the legacy behavior.According to the official news, instructions to the system administrators have been provided to ensure that your firewall rules still work. Moreover, you’ll need to check your
/etc/iptablesdirectory for any.pacsavefiles related to the following files:/etc/iptables/iptables.rules.pacsave/etc/iptables/ip6tables.rules.pacsave
If you have any of the above files, you’ll need to restore the rules manually to ensure that they work prior to the upgrade. You can perform the full system upgrade by running
pacman -Syuas root.The developers noted that most configurations should work with no changes made once upgrades to the
#ArchLinux #iptables #Linux #news #nft #Tech #Technology #updateiptablespackage have been made. However, if you are one of the system administrators who rely on either the uncommonxtablesextension or the legacy behavior, you’ll need to uninstalliptablesand installiptables-legacy. -
iptables now defaults to the nft backend
https://archlinux.org/news/iptables-now-defaults-to-the-nft-backend/