Differences

This shows you the differences between two versions of the page.

doc:howto:netfilter [2013/11/15 11:00]
lorema
doc:howto:netfilter [2014/02/16 09:29] (current)
lorema
Line 129: Line 129:
===== nftables ===== ===== nftables =====
-[[wp>nftables]] is the successor of all of the above programs. The user space utility **''nft''**. nftables is a drop in replacement for the entire ''{ip,eb,arp,ip6}tables'' user space tool set //and// associated kernel modules. It still uses the netfilter architecture for complex extensions and is part of the netfilter project.+[[wp>nftables]] is the successor of netfilter. Its user space utility **''nft''** replaces the entire ''{ip,eb,arp,ip6}tables'' user space tool set. It still uses the netfilter architecture for complex extensions and is part of the netfilter project.
The command-line user space utility is called **''nft''** and there is an API and library interface to it (''libnftables''). There is also an iptables to nft handle userspace conversion tool which will ease migration. The command-line user space utility is called **''nft''** and there is an API and library interface to it (''libnftables''). There is also an iptables to nft handle userspace conversion tool which will ease migration.
nftables is a major departure in that there is no need for deep protocol awareness in the kernel modules as everything filter related is handled by a basic virtual machine. nftables is a major departure in that there is no need for deep protocol awareness in the kernel modules as everything filter related is handled by a basic virtual machine.
Line 137: Line 137:
  * https://dev.openwrt.org/ticket/14415   * https://dev.openwrt.org/ticket/14415
-The OpenWrt developers are aware of the nftables developments, and will migrate as soon as OpenWrt adopts a 3.13 kernel. Linux kernel version 3.12 was released 2013-11-03, [[http://lkml.indiana.edu/hypermail/linux/kernel/1311.0/00914.html|Linux 3.12 released .. and no merge window yet .. and 4.0 plans?]], version 3.13 is due for end of the year.+The OpenWrt developers are aware of the nftables developments, and will migrate as soon as OpenWrt adopts a 3.13 kernel. Linux kernel version 3.13 was released 2014-01-20, [[http://lkml.indiana.edu/hypermail/linux/kernel/1311.0/00914.html|Linux 3.12 released .. and no merge window yet .. and 4.0 plans?]].
  * Anybody who wants to help in development, shall feel free to send patches:   * Anybody who wants to help in development, shall feel free to send patches:

Back to top

doc/howto/netfilter.txt · Last modified: 2014/02/16 09:29 by lorema