NFTables
约 2 分钟阅读
- Linux 3.13+
- AlpineLinux 3.19 iptables 默认为 ipatbles-nft
- RHEL 9 The ipset and iptables-nft packages have been deprecated
- 是什么?
- iptables 后继
- nft.8
- 参考
- docker 和 podman 都还没完全支持 nftables
- Adoption
- Quick reference-nftables in 10 minutesLinkwiki.nftables.org/wiki-nftables/index.php/Quick_reference-nftables_in_10_minutesLinux 3.13+ · AlpineLinux 3.19 iptables 默认为 ipatbles-nft · RHEL 9 The ipset and iptables-nft packages have been deprecated笔记:NFTables
- Migrating my iptables setup to nftablesLinkdevelopers.redhat.com/blog/2017/01/10/migrating-my-iptables-setup-to-nftablesLinux 3.13+ · AlpineLinux 3.19 iptables 默认为 ipatbles-nft · RHEL 9 The ipset and iptables-nft packages have been deprecated笔记:NFTables
- What comes after 'iptables'? Its successor, of course:
nftables - Benchmarking nftablesLinkdevelopers.redhat.com/blog/2017/04/11/benchmarking-nftablesLinux 3.13+ · AlpineLinux 3.19 iptables 默认为 ipatbles-nft · RHEL 9 The ipset and iptables-nft packages have been deprecated笔记:NFTables
- Transparent proxy with nftablesLinkhev.cc/3033.htmlLinux 3.13+ · AlpineLinux 3.19 iptables 默认为 ipatbles-nft · RHEL 9 The ipset and iptables-nft packages have been deprecated笔记:NFTables
- 开发
- google/nftablesGitHubgoogle/nftablesLinux 3.13+ · AlpineLinux 3.19 iptables 默认为 ipatbles-nft · RHEL 9 The ipset and iptables-nft packages have been deprecated笔记:NFTables - Golang
- zevenet/nftlbGitHubzevenet/nftlb nftables load balancer
- 默认规则会包含目录内配置 -
include "/etc/nftables.d/*.nft"- save 后不会有该 include 语句 - 不要 save
- 尽量使用 reload -
service nftables reload
- inet 只能用于 filter 不能用于 nat
# 所有规则
nft list ruleset
# 导出为 JSON
nft -j list ruleset
# 清除规则
nft flush ruleset
# 清除单个 famliy 规则
nft flush ruleset arp
nft flush ruleset ip
nft flush ruleset ip6
nft flush ruleset bridge
nft flush ruleset inet
nft -c -f rule.nft # 检查规则
nft -f rule.nft # 应用规则
# 转义
# nft add rule ip filter INPUT tcp dport 22 ct state new counter accept
iptables-translate -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
# 单个规则只能使用句柄删除
# 查看
nft --handle --numeric list chain inet filter input
# 删除
nft delete rule inet fltrTable input handle 10
# 清空表
nft flush table foo
# 清空链
nft flush chain foo bar
nft delete rule ip6 foo bar
nft describe tcp flags
nft describe ct_state
nft describe icmp_typegateway
- eth0 lan
- eth5 wan
- 允许作为 gateway 转发
- 允许来自 lan 的请求
table ip nat {
chain prerouting {
type nat hook prerouting priority 0;
}
chain postrouting {
type nat hook postrouting priority 100;
oif "eth5" masquerade
}
}
table ip filter {
chain input {
type filter hook input priority 0;
# 限制从 eth5 进来的流量只能访问特定端口
iifname "eth5" tcp dport { 22, 80, 443 } accept
iifname "eth5" udp dport { 22, 80, 443 } accept
# 允许来自 192.168.0.0/16 的所有流量
ip saddr 192.168.0.0/16 accept
}
chain forward {
type filter hook forward priority 0;
policy drop;
# 不转发到 192.168.66.2 的流量
ip daddr 192.168.66.2 drop;
# 允许来自 eth0 并且源地址为 192.168.0.0/16 的所有流量
ip saddr 192.168.0.0/16 iifname "eth0" oifname "eth5" accept;
# 允许从 eth5 到 eth0 的已建立连接的回应流量
iifname "eth5" oifname "eth0" ct state established accept;
}
chain output {
type filter hook output priority 0;
}
}
FAQ
Error: Could not process rule: File exists
Error: Statement after terminal statement has no effect
调整语句顺序,例如 accept、drop、masquerade 需要放在最后。
关联信息
反向链接和本文引用的外部资料。
References
GitHub
2 条- google/nftablesgithub.com/google/nftables
- zevenet/nftlbgithub.com/zevenet/nftlb
其他外链
8 条- access.redhat.com/solutions/6739041access.redhat.com/solutions/6739041
- developers.redhat.com/blog/2016/10/28/what-comes-after-iptables-its-successor-of-course-nftablesdevelopers.redhat.com/blog/2016/10/28/what-comes-after-iptables-its-successor-of-course-nftables
- developers.redhat.com/blog/2017/01/10/migrating-my-iptables-setup-to-nftablesdevelopers.redhat.com/blog/2017/01/10/migrating-my-iptables-setup-to-nftables
- developers.redhat.com/blog/2017/04/11/benchmarking-nftablesdevelopers.redhat.com/blog/2017/04/11/benchmarking-nftables
- hev.cc/3033.htmlhev.cc/3033.html
- jlk.fjfi.cvut.cz/arch/manpages/man/nft.8jlk.fjfi.cvut.cz/arch/manpages/man/nft.8
- wiki.nftables.org/wiki-nftables/index.php/Adoptionwiki.nftables.org/wiki-nftables/index.php/Adoption
- wiki.nftables.org/wiki-nftables/index.php/Quick_reference-nftables_in_10_minuteswiki.nftables.org/wiki-nftables/index.php/Quick_reference-nftables_in_10_minutes