Skip to content

Add nft support through ip(6)tables-translate#135

Open
haubentaucher wants to merge 8 commits intofwbuilder:masterfrom
haubentaucher:master
Open

Add nft support through ip(6)tables-translate#135
haubentaucher wants to merge 8 commits intofwbuilder:masterfrom
haubentaucher:master

Conversation

@haubentaucher
Copy link
Copy Markdown

The following changes add basic nftables support to make fwbuilder usable for modern routers & firewalls. It is clearly no native support of nftables, and some features such as automatic creation of conntrack helpers is missing.

b148847
6ee0fd6

Hope this helps to keep fwbuilder alive.

raddatacommunication and others added 8 commits February 1, 2018 15:24
changes were made to adjust the product to RAD Data and Communication RADView convention
Replace ip(6)tables with ip(6)tables-translate to enable transition to
nftables and extend lifetime of software.
Add nftables compatible configlets for reset and stop of firewall.
"onlink" option needs to be added if gateway is not directly connected.
This could be done automatically by looking at the IPs of all interfaces
of the firewall, comparing them to the gateway's IP. Just don't know how
to do this (yet).
iptables-translate escapes all quotes, which does not work anymore with
(ba)sh.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants