Nftables 1.0.0 Released
marc.info
marc.info
I learned ipfw. Then ipchains. Then iptables. I got quite good with handcrafting firewalls with all of those at some point. The machines they ran on (for me) range from 80486 to date.
This laptop has a ... (fumbles with various commands and searches) ...
$ sudo nft list rules
firewalld and its GUI generates a nftables based firewall.I generally use ufw on servers because it is easy for a simple host based firewall and that is iptables based still. A server host based firewall is generally all about ingress filtering. Egress can be covered more effectively at the edge and at switches/internal routers.
My laptop needs a far more complicated setup and the ruleset that is dumped by nft is almost legible in the first read. I do use a GUI but it's nice to think that I can sit down and spend some time and decide whether my stated policy is what I get at the firewall itself.
I don't yet use nft at the edge but it feels as though it might do nicely.
Your firewalling choice is not something that happens overnight. I'll mull over it for at least two more years.
> nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames
But because the Linux kernel is developed separately from user-space, and never breaks user-space, iptables (at least the API) will never go away
> This system call no longer exists on current kernels! See NOTES.
I don't think you can still use all of them.
As far as I understand, it may happen that everybody stops using the old interface (the distros choose what they compile into their kernels, I guess), and after a few years of that the kernel maintainers may decide to remove the old code, assuming it wouldn't be too much work. Don't know how likely it for this to happen in the near future, though.
[1] http://rmind.github.io/npf/intro.html
[2] https://man.netbsd.org/npf.7
Or conveniently integrated into Linux like in
[3] https://therouter.net/ and
It's my understanding that Cilium chose to do it this way because it allows low-level control of each network namespace that containers launch in, in addition to a high-level view of the system from the k8s API. This allows Cilium to build firewalling features that operate at a different level -- iptables/nftables filters on IP addresses and ports, but Cilium can filter on k8s resources and L7 protocols.
Kubernetes also has network security policy features for firewalling, that piece is implemented by plugins which do whatever they want though.
At this time, kubernetes requires you to be using iptables instead of nftables for all of this, so it will be interesting to see it running on iptables-free servers in the future.