Switch to nft interface by default

This commit is contained in:
2025-10-14 15:34:23 +03:00
parent 302e24b8df
commit a3d03d2133
8 changed files with 93 additions and 37 deletions
+28 -2
View File
@@ -1,9 +1,35 @@
name: iptables name: iptables
description: userspace CLI program used to configure the Linux packet filtering ruleset description: userspace CLI program used to configure the Linux packet filtering ruleset
version: 1.8.11 version: 1.8.11
revision: 2 revision: 3
url: https://www.netfilter.org/projects/iptables/index.html url: https://www.netfilter.org/projects/iptables/index.html
license: GPL2-only license: GPL2-only
architecture: any architecture: any
depends: ["bash"]
type: source type: source
keep:
- etc/ethertypes
- etc/iptables/iptables.rules
- etc/iptables/ip6tables.rules
depends:
- libnetfilter_conntrack
- libnfnetlink
- libnftnl
- libpcap
- nftables
downloads:
- url: https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz
extract_to: ${BPM_SOURCE}
extract_strip_components: 1
checksum: d87303d55ef8c92bcad4dd3f978b26d272013642b029425775f5bad1009fe7b2
split_packages:
- name: iptables
conflicts:
- iptables-legacy
- name: iptables-legacy
depends:
- libnetfilter_conntrack
- libnfnetlink
- libnftnl
- libpcap
conflicts:
- iptables
+6
View File
@@ -0,0 +1,6 @@
name: iptables
description: IPv6 Packet Filtering Framework
type: simple
start_cmd: /etc/esvm/scripts/ip6tables.sh
stop_cmd: /etc/esvm/scripts/iptables-flush.sh -6
exit_method: stop_command
+5
View File
@@ -0,0 +1,5 @@
#!/bin/sh
[ ! -e /etc/iptables/ip6tables.rules ] && exit 0
ip6tables-restore -w 3 /etc/iptables/ip6tables.rules || exit 1
exec ip6tables pause
+18 -11
View File
@@ -1,14 +1,21 @@
# Flush iptables (Code from archlinux) #!/bin/sh
iptables=ip$1tables # Usage: iptables-flush [-6]
if ! type -p "$iptables" &>/dev/null; then
echo "error: invalid argument" iptables=/usr/sbin/iptables
exit 1 tables="filter mangle raw"
if [ "$1" = "-6" ]; then
iptables=/usr/bin/ip6tables
else
# Only ipv4 has a nat table
tables="$tables nat"
fi fi
while read -r table; do for table in ${tables}; do
tables+=("/usr/share/iptables/empty-$table.rules") $iptables -t "$table" -F
done <"/proc/net/ip$1_tables_names" $iptables -t "$table" -X
done
if (( ${#tables[*]} )); then for chain in INPUT FORWARD OUTPUT; do
cat "${tables[@]}" | "$iptables-restore" $iptables -P "$chain" ACCEPT
fi done
+1 -1
View File
@@ -1,6 +1,6 @@
name: iptables name: iptables
description: IPv4 Packet Filtering Framework description: IPv4 Packet Filtering Framework
type: simple type: simple
start_cmd: /usr/sbin/iptables-restore /etc/iptables/iptables.rules start_cmd: /etc/esvm/scripts/iptables.sh
stop_cmd: /etc/esvm/scripts/iptables-flush.sh stop_cmd: /etc/esvm/scripts/iptables-flush.sh
exit_method: stop_command exit_method: stop_command
+5
View File
@@ -0,0 +1,5 @@
#!/bin/sh
[ ! -e /etc/iptables/iptables.rules ] && exit 0
iptables-restore -w 3 /etc/iptables/iptables.rules || exit 1
exec iptables pause
+1 -1
View File
@@ -3,7 +3,7 @@
:FORWARD DROP [0:0] :FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0] :OUTPUT ACCEPT [0:0]
-A INPUT -p icmp -j ACCEPT -A INPUT -p icmp -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT -A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -j REJECT --reject-with tcp-reset -A INPUT -p tcp -j REJECT --reject-with tcp-reset
-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable -A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable
+29 -22
View File
@@ -2,40 +2,47 @@
# BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE # BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE
# BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT # BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT
DOWNLOAD="https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz"
FILENAME="${DOWNLOAD##*/}"
# The prepare function is executed in the root of the temp directory
# This function is used for downloading files and putting them into the correct location
prepare() {
wget "$DOWNLOAD"
tar -xvf "$FILENAME" --strip-components=1 -C "$BPM_SOURCE"
}
# The build function is executed in the source directory # The build function is executed in the source directory
# This function is used to compile the source code # This function is used to compile the source code
build() { build() {
./configure --prefix=/usr \ ./configure --prefix=/usr --enable-bpf-compiler --enable-devel --enable-libipq --enable-shared
--disable-nftables \
--enable-libipq
make make
} }
# The package function is executed in the source directory # The package function is executed in the source directory
# This function is used to move the compiled files into the output directory # This function is used to move the compiled files into the output directory
package() { package_iptables() {
make DESTDIR="$BPM_OUTPUT" install
# Link to xtables-nft-multi
for x in {arp,eb,ip,ip6}tables{,-restore,-save}; do
ln -sf xtables-nft-multi "$BPM_OUTPUT"/usr/sbin/"$x"
done
ln -sf /usr/sbin/xtables-nft-multi "$BPM_OUTPUT"/usr/bin/iptables-xml
# Install esvm service
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
# Install iptables rules
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
# Install package license
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
}
package_iptables-legacy() {
make DESTDIR="$BPM_OUTPUT" install make DESTDIR="$BPM_OUTPUT" install
# Install esvm service # Install esvm service
install -Dm755 "$BPM_WORKDIR"/iptables-flush.sh "$BPM_OUTPUT"/etc/esvm/scripts/iptables-flush.sh install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
install -Dm644 "$BPM_WORKDIR"/iptables.esv "$BPM_OUTPUT"/etc/esvm/services/iptables.esv install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
# Rules from Arch Linux # Install iptables rules
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/iptables.rules install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/ip6tables.rules install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
install -Dm644 "$BPM_WORKDIR"/rules/*.rules -t "$BPM_OUTPUT"/usr/share/iptables/
ln -srt "$BPM_OUTPUT"/etc/iptables "$BPM_OUTPUT"/usr/share/iptables/{empty,simple_firewall}.rules
# Install package license # Install package license
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/LICENSE install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
} }