lanefu · @lanefu
71 followers · 524 posts · Server social.linux.pizza

Wanted to share a recent project of mine from past few weeks to turn my r5s into a really potent pure debian Linux router that was sane to manage.

I was able to successfully switch over this weekend and retire my edgerouter-6p.

The formula is basically stuff and -- the lynchpin solution for sanely doing robust zone-to-zone firewalls using

Repo linked below has more details:

github.com/lanefu/clammy-ng

#nanopi #sbc #ansible #systemd #netplan #dnsmasq #frrouting #foomuuri #nftables

Last updated 2 years ago

Linux Magazine · @linuxmagazine
7324 followers · 352 posts · Server fosstodon.org

From Linux Update: Frank Hoffman shows you how nftables simplifies the process of creating and maintaining firewall rules linux-magazine.com/Issues/2023

#firewall #nftables #iptables #foss #filter #packets #linux #netfilter #opensource

Last updated 2 years ago

Vivien à la masse ⏚ · @gugurumbe
53 followers · 924 posts · Server mastouille.fr

Question réseau !

J’ai un bouquet d’adresses sur ma machine. J’aimerais utiliser de préférence l’une de mes adresses pour me connecter à internet, mais une autre spécifique lorsque le port de destination est 25 (merci google).

Je soupçonne que peut m’aider, mais j’ai du mal à trouver de la documentation.

Est-ce que je peux utiliser nftables ? Si oui, comment ?

#ipv6 #nftables

Last updated 2 years ago

Frehi · @frehi
86 followers · 1328 posts · Server fosstodon.org

@jerry
I once had problems because newer iptables on is basically a compatibility layer using in the background. Flushing all rules with iptables would remove the nftables rules but not the rules. I had to use iptables-legacy to flush the rules.

#debian #nftables #netfilter

Last updated 2 years ago

Alexandre · @alelab
31 followers · 190 posts · Server mastodon.bsd.cafe

@stefano works well but setup is really not simple. or are more complicated for me than . Even is easier to understand than NFTables or IPTables.
I already managed a small server powered by : I love to manually install and setup my apps to understand who they work. I learn a lot this way.

#archlinux #nftables #iptables #pf #ipfw #freebsd

Last updated 2 years ago

@spirillen
Good one. Yes we remember reading once somewhere that is being replaced with .

Do we know the timeline?

BTW the notabug repo we shared is definately not official. The entity officially posts to tracker2.postman.i2p, they just share the torrent there. A comment there would be seen, perhaps??

#iptables #nftables

Last updated 2 years ago

Thorsten Leemhuis (1/4) · @kernellogger
1886 followers · 1475 posts · Server fosstodon.org

1.0.8 is out:
lore.kernel.org/all/ZLEr3Eg59H

"""
- Support for setting meta and ct mark from other fields in rules […]

- Enhacements for -o/--optimize to deal with NAT statements […]

- Support for stateful statements in anonymous maps, such as counters. […]

- Simplify reset command syntax. […]

- Allow for updating devices on existing netdev chain […]

- JSON support for table and chain comments […]

- JSON support for inner/tunnel matching. […]
"""

#nftables #linux #kernel #linuxkernel #firewall

Last updated 2 years ago

Robert von Burg :vegan: :tux: · @eitch
82 followers · 889 posts · Server mstdn.gsi.li

@erroddy @nixCraft I don't understand these issues against . We have to learn many new things in all the time:
- replaced by ip
- paths in the kernel for various things
- vs
- vs
- etc.

This trend won't stop i am sure =)

itsfoss.com/deprecated-linux-c

#systemd #linux #ifconfig #iptables #nftables #x11 #wayland

Last updated 2 years ago

Freeaqingme · @freeaqingme
21 followers · 15 posts · Server fosstodon.org

It's really hard to fathom that Docker doesn't have support up to this day.

#nftables

Last updated 2 years ago

Marek Küthe · @mark22k
100 followers · 640 posts · Server layer8.space

Aussage von ChatGPT von nftables: "Die Fehlermeldung weist auf mehrere Syntaxfehler hin, die in der Datei "/etc/nftables.conf" vorliegen. Die genaue Ursache kann anhand der bereitgestellten Fehlermeldung nicht eindeutig festgestellt werden[...]"
Mhh, nichtmal ChatGPT findet die Fehlermeldung gut.

#chatgpt #nftables

Last updated 2 years ago

AskUbuntu · @askubuntu
115 followers · 1931 posts · Server ubuntu.social
AskUbuntu · @askubuntu
115 followers · 1943 posts · Server ubuntu.social
Thomas Frans 🇺🇦 · @thomy2000
38 followers · 2253 posts · Server social.linux.pizza

It's always DNS. Always. Except when it's that mediocre nftables setup you did a while ago and forgot all about... Hours of debugging fun guaranteed, all to find out that you should probably have left those forwarding hooks alone. They weren't hurting anyone.

#network #firewall #nftables

Last updated 2 years ago

· @frox
90 followers · 1197 posts · Server tooting.ch

Success! I have tunneled my way out of with the help of running ontop of on a
This setup is less prone to breakage than my previous hacked-together one. And clients get a global !

#ipv6 #nftables #vps #openwrt #wireguard #cgnat

Last updated 2 years ago

Andy Smith · @grifferz
249 followers · 1295 posts · Server social.bitfolk.com

Think I am finally getting the hang of configuring host-based nftables firewall through Ansible with this role.
Can't QUITE understand why I can't just do a group's rules in group_vars/foo.yml and instead have to use this merged-groups thing, but I do have firewall rules composable by group and host which is really all I need…
github.com/ipr-cnrs/nftables

#ansible #nftables

Last updated 2 years ago

:oc: xakan, barbedouce :oc: · @xakan
458 followers · 1687 posts · Server social.zdx.fr

Je crois que reste le truc le plus mal documenté du monde.

#nftables

Last updated 2 years ago

Fran :clapidi: :verifroue: · @alter_unicorn
390 followers · 2929 posts · Server masto.bike

iptables -> 🗑️

fail2ban w/nftables ✅

🍾

#nftables

Last updated 2 years ago

Daniel Lakeland · @dlakelan
119 followers · 973 posts · Server mastodon.sdf.org

Ok, went down a slight rabbit hole... You can use to log to the nflog facility. or can read from the nflog queue and report info on the packets. Nftables can sample the packets randomly using numgen random mod 1000 < 50 I can sample 5% of packets (or whatever) if the output is easily readable by I can turn the network visibility issue into a data analysis issue. What's the best way to read the output? tshark json?

#nftables #packets #tcpdump #tshark #julialang

Last updated 2 years ago

a little understanding · @lewdmachines
25 followers · 51 posts · Server mastodon.social

spent a fair bit of time with the firewalld implementation of nftables today. every single time I have to deal with a Linux firewall system I long for the simplicity of ipfw rules/config

why is Linux such a convoluted mess at this in comparison?

#linux #freebsd #nftables #firewall

Last updated 3 years ago

hexathos 😷🤘 · @hexathos
87 followers · 39 posts · Server mastodon.social

Gewundert warum das lab vlan keine ips bezieht... komplette vlan config geprüft... nur um festzustellen das ich es in nicht freigab...

#nftables

Last updated 3 years ago