home.social

#iptables — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iptables, aggregated by home.social.

fetched live
  1. Every time I have anything to do with #nftables I'm reminded just how much I dislike it (and #iptables before it) and how great #OpenBSD #pf is.

  2. @mathew we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.

    I think it will take years before nftables works with everything just like it is with ipv6.

  3. @mathew we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.

    I think it will take years before nftables works with everything just like it is with ipv6.

  4. Как eBPF меняет правила безопасности и наблюдаемости в Kubernetes

    eBPF часто подают как кнопку «ускорить Kubernetes», но на практике всё сложнее. Он действительно помогает уйти от тяжёлых цепочек iptables, снизить задержки и получить наблюдаемость ближе к ядру Linux. Но стоит перейти от L4 к L7, включить глубокую инспекцию трафика или mTLS — и бесплатная магия заканчивается. Разбираем, где eBPF меняет правила игры, а где всё ещё приходится считать оверхед. Читать разбор

    habr.com/ru/companies/otus/art

    #eBPF #Kubernetes #Cilium #kubeproxy #iptables #XDP #observability #сетевые_политики #безопасность_кластера #L7фильтрация

  5. Создание Android-смартфона с упором на приватность

    Практический опыт ограничения приложений на Android В статье рассматривается практический опыт настройки Android‑смартфона с root‑доступом для ограничения сетевого взаимодействия приложений и управления их разрешениями. Анализ трафика, whitelist/blacklist доменов, Magisk, iptables и создание контролируемой среды на устройстве.

    habr.com/ru/articles/1044080/

    #Android #Magisk #Root #Приватность #Информационная_безопасность #Iptables #Firewall #Linux #Mobile_Security #android_security

  6. Простая настройка машины под Linux как роутера — NAT+iptables+dnsmasq

    Короткое описание, как я настраивал себе на Linux-машине роутер с пересылкой трафика в интернет, собственным DNS и DHCP. Простое и элегантное решение.

    habr.com/ru/articles/1033562/

    #iptables #bonding #dns #linux #dnsmasq

  7. Jugando con Kathará para emular redes TCP/IP! 🚀

    Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).

    Se ve muy interesante para incorporarla a las clases!

    Seguramente haga algo de contenido sobre esto 🙂

    youtu.be/CPYsuUeR6cE

    +Info: kathara.org/

    #uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables

  8. Jugando con Kathará para emular redes TCP/IP! 🚀

    Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).

    Se ve muy interesante para incorporarla a las clases!

    Seguramente haga algo de contenido sobre esto 🙂

    youtu.be/CPYsuUeR6cE

    +Info: kathara.org/

    #uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables

  9. От iptables к nftables: O(n) против O(1) на практике

    Если администрировать Linux-сервера достаточно долго, рано или поздно сталкиваешься с сетевой фильтрацией. Где-то нужно закрыть лишние порты, где-то ограничить доступ между сегментами сети, а где-то настроить NAT. На практике это почти всегда приводит к iptables: таблицы, цепочки, правила — и со временем конфигурация начинает напоминать археологический слой. Правила копируются, дополняются, теряют актуальность, и через пару лет уже сложно понять, почему конкретное правило вообще существует. В этой статье разберёмся, как появился nftables, чем он отличается от привычного iptables, как устроена его архитектура и как на практике использовать его для настройки firewall на Linux-сервере.

    habr.com/ru/companies/gnivc/ar

    #nftables #netfilter #iptables #linux #benchmark

  10. Три слоя защиты сервера: ipset, auto-block и CrowdSec

    Ваши логи забиты попытками входа в .env , .git и wp-login.php ? Пока бот стучится в Nginx, ваш сервер уже тратит драгоценные ресурсы. Я решил перенести фильтрацию в ядро Linux и делюсь рабочим кейсом эшелонированной обороны на базе ipset и CrowdSec .

    habr.com/ru/articles/1019778/

    #WAF #ipset #iptables #CrowdSec #Битрикс #защита_сервера #безопасность #Linux #bashскрипты #информационная_безопасность

  11. ¿Conflicto entre iptables y arptables en @archlinux?

    No es un error, es una migración.

    Al actualizar mi Arch me encontré con este mensaje. Lejos de ser un problema, es parte de la transición hacia #nftables como backend unificado.

    🔍 ¿Qué está pasando?

    El paquete moderno #iptables (1.8.11-4) ahora incluye funcionalidad ARP y Ethernet.

    Ya no necesita paquetes separados como #arptables o #ebtables.

    #pacman te avisa del conflicto para que no queden paquetes huérfanos.

    (1/2)

  12. ¿Conflicto entre iptables y arptables en @archlinux?

    No es un error, es una migración.

    Al actualizar mi Arch me encontré con este mensaje. Lejos de ser un problema, es parte de la transición hacia #nftables como backend unificado.

    🔍 ¿Qué está pasando?

    El paquete moderno #iptables (1.8.11-4) ahora incluye funcionalidad ARP y Ethernet.

    Ya no necesita paquetes separados como #arptables o #ebtables.

    #pacman te avisa del conflicto para que no queden paquetes huérfanos.

    (1/2)

  13. Arch Linux now uses the “nft” backend for iptables!

    iptables is a utility program for Linux that provides you a method to configure filtering rules for IP protocol, configured as different Netfilter modules. It works as a firewall to implement a different set of rules that change how the packets are treated.

    Arch Linux used to provide two packages for this utility, which included:

    • iptables-nft: This package contains the iptables binary with nft as the backend
    • iptables: This package contains the iptables binary with the legacy backend

    The Arch Linux development team has now implemented the nft backend as the default backend for the iptables utility, which caused the iptables-nft package to be considered a legacy package. Similarly, a new package, called iptables-legacy, has been created to preserve the legacy behavior.

    According to the official news, instructions to the system administrators have been provided to ensure that your firewall rules still work. Moreover, you’ll need to check your /etc/iptables directory for any .pacsave files related to the following files:

    • /etc/iptables/iptables.rules.pacsave
    • /etc/iptables/ip6tables.rules.pacsave

    If you have any of the above files, you’ll need to restore the rules manually to ensure that they work prior to the upgrade. You can perform the full system upgrade by running pacman -Syu as root.

    The developers noted that most configurations should work with no changes made once upgrades to the iptables package have been made. However, if you are one of the system administrators who rely on either the uncommon xtables extension or the legacy behavior, you’ll need to uninstall iptables and install iptables-legacy.

    #ArchLinux #iptables #Linux #news #nft #Tech #Technology #update
  14. Arch Linux now uses the “nft” backend for iptables!

    iptables is a utility program for Linux that provides you a method to configure filtering rules for IP protocol, configured as different Netfilter modules. It works as a firewall to implement a different set of rules that change how the packets are treated.

    Arch Linux used to provide two packages for this utility, which included:

    • iptables-nft: This package contains the iptables binary with nft as the backend
    • iptables: This package contains the iptables binary with the legacy backend

    The Arch Linux development team has now implemented the nft backend as the default backend for the iptables utility, which caused the iptables-nft package to be considered a legacy package. Similarly, a new package, called iptables-legacy, has been created to preserve the legacy behavior.

    According to the official news, instructions to the system administrators have been provided to ensure that your firewall rules still work. Moreover, you’ll need to check your /etc/iptables directory for any .pacsave files related to the following files:

    • /etc/iptables/iptables.rules.pacsave
    • /etc/iptables/ip6tables.rules.pacsave

    If you have any of the above files, you’ll need to restore the rules manually to ensure that they work prior to the upgrade. You can perform the full system upgrade by running pacman -Syu as root.

    The developers noted that most configurations should work with no changes made once upgrades to the iptables package have been made. However, if you are one of the system administrators who rely on either the uncommon xtables extension or the legacy behavior, you’ll need to uninstall iptables and install iptables-legacy.

    #ArchLinux #iptables #Linux #news #nft #Tech #Technology #update
  15. [Перевод] Настройка сети в Kubernetes: основы CNI

    Kubernetes-кластер без сети — не кластер, а просто набор несвязанных компонентов. Чтобы «оживить» его, важно понимать, что такое Container Network Interface (CNI) и как он работает. В статье — детальный разбор механизма CNI: что такое CNI-плагин, как он запускается и какие операции выполняет в кластере. В конце работа CNI демонстрируется на примере кастомного плагина. Для желающих глубже погрузиться в тему есть список дополнительных материалов.

    habr.com/ru/companies/flant/ar

    #сеть #cni #cniплагин #Container_Network_Interface #ipam #containerd #vxlan #static_routing #iptables

  16. Firewalls en Linux: ¿Cómo funcionan realmente por dentro?

    ¿Alguna vez te sentiste abrumado/a con la terminología de firewalls en Linux?
    ¿No sabés si usar iptables o nftables, firewalld, firewall-cmd, firewall-config, ufw, etc.?

    Todos comparten una arquitectura interna que vale la pena entender para comprender el rol de cada herramienta.

    👉 youtu.be/EqGP4Pi-7QU

    ¿Vos ya usás nftables? O tu sistema usa iptables (legacy)?💬

    #Linux #Firewall #Ciberseguridad #SysAdmin #Nftables #Iptables #DevOps

  17. Firewalls en Linux: ¿Cómo funcionan realmente por dentro?

    ¿Alguna vez te sentiste abrumado/a con la terminología de firewalls en Linux?
    ¿No sabés si usar iptables o nftables, firewalld, firewall-cmd, firewall-config, ufw, etc.?

    Todos comparten una arquitectura interna que vale la pena entender para comprender el rol de cada herramienta.

    👉 youtu.be/EqGP4Pi-7QU

    ¿Vos ya usás nftables? O tu sistema usa iptables (legacy)?💬

    #Linux #Firewall #Ciberseguridad #SysAdmin #Nftables #Iptables #DevOps

  18. Как подружить KeeneticOS 5 с xHTTP

    KeeneticOS из коробки закрывает большинство бытовых задач, но как только появляется требование рулить трафиком по-своему, быстро упираешься в нюансы. Я собрал рабочую схему на Keenetic Hopper: Entware + Xray-core (TUN) + policy-based routing через fwmark и отдельную таблицу маршрутизации. Главный фокус на эксплуатации, я покажу минимальный чек-лист диагностики, и как сделать конфигурацию самовосстанавливающейся, чтобы больше никогда не залазить руками. Статья - практическая инструкция: команды, конфиги и понятные критерии.

    habr.com/ru/articles/1010414/

    #KeeneticOS #Xraycore #iptables #раздельное_туннелирование #domainbased_routing

  19. ¿Que en Kali Linux el comando iptables usan, en espacio del núcleo, a nftables?

    Sí, mirá 👇

    Qué interesantes cosas van a salir en el próximo video en el canal de youtube de #juncotic!

    Y con estos detalles adicionales, también en el blog 📚

    Estén atentos/as!!

    #iptables #nftables #nft

  20. ¿Que en Kali Linux el comando iptables usan, en espacio del núcleo, a nftables?

    Sí, mirá 👇

    Qué interesantes cosas van a salir en el próximo video en el canal de youtube de #juncotic!

    Y con estos detalles adicionales, también en el blog 📚

    Estén atentos/as!!

    #iptables #nftables #nft

  21. Se viene contenido nuevo en los cursos de #iptables, #nftables, y en el canal de #youtube de #juncotic !

    Esta vez, aclarando una confusión generalizada sobre los firewalls en Linux:
    #nftables, #nft, #iptables, #firewalld, firewall-cmd, firewall-config, #ufw, etc.

    Vamos a ver qué son, y cómo se relacionan entre si.

    Si quieren sigan al canal para estar al tanto!

    🔗 youtube.com/juncotic?sub_confi

    También un par de actualizaciones en el blog, luego les aviso.

    #firewallcmd,f#irewallconfig #ufw #linux

  22. Se viene contenido nuevo en los cursos de #iptables, #nftables, y en el canal de #youtube de #juncotic !

    Esta vez, aclarando una confusión generalizada sobre los firewalls en Linux:
    #nftables, #nft, #iptables, #firewalld, firewall-cmd, firewall-config, #ufw, etc.

    Vamos a ver qué son, y cómo se relacionan entre si.

    Si quieren sigan al canal para estar al tanto!

    🔗 youtube.com/juncotic?sub_confi

    También un par de actualizaciones en el blog, luego les aviso.

    #firewallcmd,f#irewallconfig #ufw #linux

  23. Estoy grabando un nuevo video para el canal de youtube de #juncotic y para los cursos de iptables y nftables... busco doc sobre la arquitectura interna de netfilter en Linux, y me encuentro con un artículo mío en mi blog, con toda la info... cosas que pasan xD

    Se los dejo como spoiler del próximo video 😆

    juncotic.com/nftables-vs-iptab

    Y el link al canal por si quieren sumarse!
    🔗 youtube.com/juncotic?sub_confi

    #linux #iptables #nftables #firewall #netfilter

  24. Estoy grabando un nuevo video para el canal de youtube de #juncotic y para los cursos de iptables y nftables... busco doc sobre la arquitectura interna de netfilter en Linux, y me encuentro con un artículo mío en mi blog, con toda la info... cosas que pasan xD

    Se los dejo como spoiler del próximo video 😆

    juncotic.com/nftables-vs-iptab

    Y el link al canal por si quieren sumarse!
    🔗 youtube.com/juncotic?sub_confi

    #linux #iptables #nftables #firewall #netfilter

  25. 🚀 Se termina el mes, pero todavía estás a tiempo de invertir en tu futuro profesional!

    📚 ¿Qué podés aprender en #JuncoTIC?

    🐧 GNU/Linux & SysAdmin
    🔒 Ciberseguridad & Redes
    🐍 Desarrollo Web con Python y Flask.

    ✨ BONUS: cursos gratuitos de introducción a GNU/Linux y a Flask 🎁

    ⏳ Sólo por 5 días, el tiempo corre!

    👉 juncotic.com/cursos/

    Te esperamos en el aula virtual! 🎓

    #Linux #Ciberseguridad #Programación #CursosOnline #SysAdmin #Python #Redes #ssh #iptables #nftables #lpic #flask

  26. 🚀 Se termina el mes, pero todavía estás a tiempo de invertir en tu futuro profesional!

    📚 ¿Qué podés aprender en #JuncoTIC?

    🐧 GNU/Linux & SysAdmin
    🔒 Ciberseguridad & Redes
    🐍 Desarrollo Web con Python y Flask.

    ✨ BONUS: cursos gratuitos de introducción a GNU/Linux y a Flask 🎁

    ⏳ Sólo por 5 días, el tiempo corre!

    👉 juncotic.com/cursos/

    Te esperamos en el aula virtual! 🎓

    #Linux #Ciberseguridad #Programación #CursosOnline #SysAdmin #Python #Redes #ssh #iptables #nftables #lpic #flask

  27. Ich bin also zu dämlich in Ubuntu einen Port-Redirector auf eine andere Maschine einzurichten.
    Oder ich mag Linux-Netzwerkkonfigurationdateien nicht.
    Oder beides. 🤯

    #iptables #ufw #before.rules #prerouting #forward #postrouting

  28. Ich bin also zu dämlich in Ubuntu einen Port-Redirector auf eine andere Maschine einzurichten.
    Oder ich mag Linux-Netzwerkkonfigurationdateien nicht.
    Oder beides. 🤯

    #iptables #ufw #before.rules #prerouting #forward #postrouting

  29. Se vienen cositas próximamente en el blog y en el canal de YouTube 💪

    Intentando aclarar algunos conceptos fundamentales de SSH para poder utilizarlo como un pro y no morir en el intento 🚀

    ¿Todavía no nos siguen? 👇

    ▶️ youtube.com/juncotic?sub_confi

    📚 juncotic.com/blog

    🎓 juncotic.com/cursos

    ¡Los esperamos para seguir aprendiendo juntos!

    #gnu #linux #ssh #curso #firewall #iptables #nftables #wireshark #redes #tcpip #ciberseguridad #python #flask #shellscripting #juncotic

  30. Se vienen cositas próximamente en el blog y en el canal de YouTube 💪

    Intentando aclarar algunos conceptos fundamentales de SSH para poder utilizarlo como un pro y no morir en el intento 🚀

    ¿Todavía no nos siguen? 👇

    ▶️ youtube.com/juncotic?sub_confi

    📚 juncotic.com/blog

    🎓 juncotic.com/cursos

    ¡Los esperamos para seguir aprendiendo juntos!

    #gnu #linux #ssh #curso #firewall #iptables #nftables #wireshark #redes #tcpip #ciberseguridad #python #flask #shellscripting #juncotic

  31. If you're running any of our firewall scripts, you'll probably want to update them!

    They're all now reworked to keep their defined iptables chains attached to the top of the INPUT chain, to make sure default policies don't just override them. At least two of our servers had ended up not actually blocking IPs before this rewrite.

    github.com/qwebltd/Useful-scri

    github.com/qwebltd/Useful-scri

    github.com/qwebltd/Useful-scri

    #iptables #linux #firewall #serveradmin #security #secops #hosting

  32. If you're running any of our firewall scripts, you'll probably want to update them!

    They're all now reworked to keep their defined iptables chains attached to the top of the INPUT chain, to make sure default policies don't just override them. At least two of our servers had ended up not actually blocking IPs before this rewrite.

    github.com/qwebltd/Useful-scri

    github.com/qwebltd/Useful-scri

    github.com/qwebltd/Useful-scri

    #iptables #linux #firewall #serveradmin #security #secops #hosting

  33. Últimas horas de la promoción de precios mínimos de Febrero! 🔥

    No pierdan la oportunidad de mejorar sus perfiles profesionales! 🎓

    Pueden encontrar los mejores precios a todos nuestros cursos en nuestro sitio web:

    juncotic.com/cursos

    Los esperamos!

    Para pagos desde Argentina (transferencia, MercadoPago):
    [email protected]

    #linux #curso #python #flask #wireshark #ssh #iptables #nftables #tcpip #juncotic

  34. Últimas horas de la promoción de precios mínimos de Febrero! 🔥

    No pierdan la oportunidad de mejorar sus perfiles profesionales! 🎓

    Pueden encontrar los mejores precios a todos nuestros cursos en nuestro sitio web:

    juncotic.com/cursos

    Los esperamos!

    Para pagos desde Argentina (transferencia, MercadoPago):
    [email protected]

    #linux #curso #python #flask #wireshark #ssh #iptables #nftables #tcpip #juncotic

  35. Invertir en tu conocimiento es la única apuesta segura 🚀

    Por los próximos 5 días, todos los cursos de #JuncoTIC están al mejor precio en Udemy!

    Si tenés ganas de dominar GNU/Linux, entender cómo funcionan las redes TCP/IP, o desarrollar sitios web con #Python y #Flask, esta es la oportunidad!

    👇 Todos los cursos con el descuento acá:

    juncotic.com/cursos

    Dudas? Otras formas de pago?
    💬 [email protected]

    #Linux #SysAdmin #IT #python #ssh #nftables #iptables #tcpip #flask #wireshark

  36. Securing Apache is critical for any production Linux server.
    This guide covers iptables firewall rules, blocking unauthorized access, and protecting custom Apache ports as part of a complete Linux hardening strategy.

    🔗 shorturl.at/5799f

    #Linux #Apache #HTTP #iptables #ServerHardening #DevOps #SysAdmin #CyberSecurity #aws #tech

  37. Ох какое я себе весёлое родео устроил решив ради лулзов убрать всякие легаси фичи касающиеся iptables из ядра на домашнем сервере и перекатиться на nftables.

    Даже Docker со всем его хозяйством перетащил.

    Вы спросите зачем?

    Я скажу, что почему бы и нет 🤷‍♂️

    #log #Linux #iptables #nftables #firewall #Docker #troubleshooting