fff-firewall: Switch from ip/ebtables to nftables #275
No reviewers
Labels
No Label
RFC
RFT
WIP
blocked
bsp
bug
build/scripts/tools
duplicate
feature
fixed
layer3
mantis
more details required
needs changes
node
packages/fff
rejected
security
trivial
upstream
No Milestone
No Assignees
2 Participants
Notifications
Due Date
No due date set.
Blocks
#284 layer3: add option to enable stateful firewall on client network
freifunk-franken/firmware
#289 OpenWrt: bump to v23.05
freifunk-franken/firmware
Reference: freifunk-franken/firmware#275
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "fbl:openwrt22-nftables"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Include nftables and appropriate modules. Translate ip- and ebtables
rules to their nftables counterparts. Remove ip/ebtables and modules.
This change intentionally tries to keep structural changes at a minimum
to keep the rule translation comprehensible.
kmod-nft-bridge is not required for fff-node, because it was merged into
a single kernel module since Linux 4.17:
[1]
02c7b25e5f
[2]
fbaf48387e
Based on #249
Fixes: #252
afd737774f
to003172bd5e
Changes:
003172bd5e
to8be918ad49
Changes:
WIP: fff-firewall: Switch from ip/ebtables to nftablesto fff-firewall: Switch from ip/ebtables to nftablesBei der commit message gehört noch das
WIP:
weg.WIP:
aus der commit message entfernt und applied.Pull request closed