Improving Network Performance with Linux Flowtables
ubicloud.com
ubicloud.com
I feel like from an abstraction standpoint, a lot of these concepts get lost when you transition to Windows and in either direction, these pre/post chains never quite made sense to me on the surface. Though, I'm positive it's because I'm not a developer or sysadmin in linux daily. I imagine there's some fascinating stuff you can do.
[0] https://upload.wikimedia.org/wikipedia/commons/3/37/Netfilte...
Could have been six lines by combining these two lines:
ip protocol tcp counter flow offload @ubi_flowtable
ip protocol udp counter flow offload @ubi_flowtable
into: meta l4proto { tcp, udp } flow offload @ubi_flowtable
Also, their changes only work for IPv4. The above would work for both IPv4 and IPv6.Also, happy to answer if there are any questions.
https://firewalld.org/2023/05/nftables-flowtable
Documentation:
https://wiki.nftables.org/wiki-nftables/index.php/Flowtables
For example sending packets from a single connection over multiple links round-robin. The cache will remember only one link and route all packets over that link.
And packets in offloaded connections will bypass nftables rate/bandwidth limits and counters.
https://www.kernel.org/doc/Documentation/networking/nf_flowt...
-edit- I know userspace networking may not be relevant in the authors case but it is of interest to me.
however I think in most cases skipping kernel might not be such a great idea, a lot of kernel features are there for a reason (e.g. like routing/arp lookup, fragmentation/reassembly), if you skip them, it means you have to implement those features in user-space...
Just putting out there that OpenStack is open source, already exists, very feature complete, and there are even hosting providers that will give you your own OpenStack control plane and only bill you for the resources you use. Only one provider in the US, but several in Europe.
No need to deploy and manage your own clusters on bare metal. They do it all for you and just give you an API, same as AWS. Way better than managing your own stack. The fact that more providers aren't doing this kind of blows my mind. But they probably prefer the proprietary walled garden, easier to keep customers from moving.
-- disgruntled user
Nftables and the netfilter project is the firewall implementation in Linux.
The legacy and beloved iptables format is fully replaced nowadays by nftables. You don't have to learn anything new because the iptables command line is just a compatibility layer on top of nftables with full compatibility. When you insert iptables rules, they get translated to nftables seamlessly. This has been the default on all major distros for years.
Converting to nftables has a few neat advantages such as much improved set/map and verdict tables support, unified IPv4, IPv6 and bridge rules, etc. But you don't have to. Everything old still works.
Flow tables is an optional feature of netfilter, I think originally meant to interface with hardware NAT accelerators in cheap routers, but it also has a pure software default implementation that can speed things up in some cases. That's what is being discussed in this article.
You use nftables to define and hook into flow tables. They work together, not against each other.