Generating much excitement back in 2018 was bpfilter for the potential to better Linux's firewall and packet filtering by making it more robust and performance. Recently work on this BPF-based firewall solution was renewed and the performance potential over iptables and nftables is looking very good for the future with more feature work planned around new matches and targets, containers integration, in-place upgrades support, privilege separation, and BPF code optimization support. . This year the BPF-based firewall code work was taken up by Facebook's Dmitrii Banshchikov and he's trying to push the code along now. Ahead of the next iteration of these patches, Dmitrii presented at this week's Linux Plumbers Conference on the effort. The bpfilter firewall support so far with these patches allows processing basic rules in INPUT/OUTPUT chains and translating them into XDP/TC programs. Leveraging BPF, the potential is there for security advantages, more robust firewall rule handling, and being more performant than iptables/nftables. The link for this article located at Phoronix is no longer available. . Reintroducing eBPF-centric security tool bpfilter, offering enhanced speed and protection compared to classic utilities such as iptables.. BPF Firewall, bpfilter Performance, Firewall Optimization. . Brittany Day
This article will look at ways for users to get more out of that faithful but somewhat dull firewall. In particular, we will look at traffic shaping, a technique that prevents high-bandwidth traffic like Napster from making other Internet applications, such . . . . This article will look at ways for users to get more out of that faithful but somewhat dull firewall. In particular, we will look at traffic shaping, a technique that prevents high-bandwidth traffic like Napster from making other Internet applications, such as Web browsing and gaming, unusable. By making some simple adjustments to the Linux kernel, users can implement an effective traffic shaping setup that ensures that the Web traffic can flow smoothly, even when a lot of outsiders are busy working with your Napster store. By restricting certain types of traffic which may otherwise dominate the Internet link, firewalls can not only optimize bandwidth but can also serve as an effective tool against certain types of 'Denial of Access' attacks. As most readers know, the firewall is a fundamental component of all computer security strategies. The firewall is positioned between the 'always-on' Internet connection provided by the local Internet Service Provider (ISP) and the Internet connection. It examines incoming and outgoing packets, marks them according to some criteria and allows or denies access based on the firewall's policy. However, the simple firewall is not only restricted to safeguarding the user's valuable information - it can also optimize the user's bandwidth. The link for this article located at is no longer available. . Explore methods to optimize Linux firewall configurations using traffic shaping strategies to boost bandwidth efficiency and protect against DoS attacks. Linux Firewall, Traffic Shaping, Bandwidth Management, Denial Of Service, Optimization Techniques. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.