firmware/src/packages/fff/fff-node/files/usr/lib/firewall.d
Fabian Bläse 8be918ad49 WIP: fff-firewall: Switch from ip/ebtables to nftables
Include nftables and appropriate modules. Translate ip- and ebtables
rules to their nftables counterparts. Remove ip/ebtables and modules.

This change intentionally tries to keep structural changes at a minimum
to keep the rule translation comprehensible.

kmod-nft-bridge is not required for fff-node, because it was merged into
a single kernel module since Linux 4.17:
[1] 02c7b25e5f
[2] fbaf48387e

Fixes: #252

Signed-off-by: Fabian Bläse <fabian@blaese.de>
Co-authored-by: Johannes Kimmel <fff@bareminimum.eu>
2023-04-06 22:04:20 +02:00
..
05-setup-batman-chains WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
06-disable-forwarding WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
30-client-dhcp WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
30-client-dhcpv6 WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
30-client-ra WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
31-node-dhcp WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
31-node-dhcpv6 WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
31-node-ra WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
35-mc WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
35-mc-arp WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
35-mc-ping WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
36-mc-policy WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
40-local-node WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00
40-nft-counter WIP: fff-firewall: Switch from ip/ebtables to nftables 2023-04-06 22:04:20 +02:00