Submit Search
Upload
Nft sync devel-pdf
•
0 likes
•
1,898 views
Arturo Borrero
Follow
Report
Share
Report
Share
1 of 19
Download now
Download to read offline
Recommended
Nft sync users-pdf
Nft sync users-pdf
Arturo Borrero
Hanz and Franz
Hanz and Franz
primeteacher32
Fun with TCP Packets
Fun with TCP Packets
Security B-Sides
IFB cloud: Integration of snakemake workflows in an appliance designed for Ch...
IFB cloud: Integration of snakemake workflows in an appliance designed for Ch...
Claire Rioualen
Pushing Python: Building a High Throughput, Low Latency System
Pushing Python: Building a High Throughput, Low Latency System
Kevin Ballard
XmppTalk
XmppTalk
Pharo
Pharo 64bits
Pharo 64bits
Pharo
SNMP, for those times you can't install the Zabbix agent. - Zabbix Conference...
SNMP, for those times you can't install the Zabbix agent. - Zabbix Conference...
Andrew Nelson
Recommended
Nft sync users-pdf
Nft sync users-pdf
Arturo Borrero
Hanz and Franz
Hanz and Franz
primeteacher32
Fun with TCP Packets
Fun with TCP Packets
Security B-Sides
IFB cloud: Integration of snakemake workflows in an appliance designed for Ch...
IFB cloud: Integration of snakemake workflows in an appliance designed for Ch...
Claire Rioualen
Pushing Python: Building a High Throughput, Low Latency System
Pushing Python: Building a High Throughput, Low Latency System
Kevin Ballard
XmppTalk
XmppTalk
Pharo
Pharo 64bits
Pharo 64bits
Pharo
SNMP, for those times you can't install the Zabbix agent. - Zabbix Conference...
SNMP, for those times you can't install the Zabbix agent. - Zabbix Conference...
Andrew Nelson
Offloading Linux LAG Devices Via Open vSwitch and TC
Offloading Linux LAG Devices Via Open vSwitch and TC
Netronome
Open Source Monitoring Tools Shootout
Open Source Monitoring Tools Shootout
tomdc
Cfgmgmtcamp 2024 — eBPF-based Security Observability & Runtime Enforcement wi...
Cfgmgmtcamp 2024 — eBPF-based Security Observability & Runtime Enforcement wi...
Raphaël PINSON
Tcpdump hunter
Tcpdump hunter
Andrew McNicol
iptables 101- bottom-up
iptables 101- bottom-up
HungWei Chiu
Unifying Network Filtering Rules for the Linux Kernel with eBPF
Unifying Network Filtering Rules for the Linux Kernel with eBPF
Netronome
opensource Monitoring Tool , an overview
opensource Monitoring Tool , an overview
Kris Buytaert
OSMC 2008 | Monitoring Tools Shootout by Tom De Cooman
OSMC 2008 | Monitoring Tools Shootout by Tom De Cooman
NETWAYS
HPE NonStop GTUG Berlin - 'Yuma' Workshop
HPE NonStop GTUG Berlin - 'Yuma' Workshop
Thomas Burg
6-ZeroLab_decentralized_applications-2008.pptx
6-ZeroLab_decentralized_applications-2008.pptx
ClaudioTebaldi2
Troubleshooting .net core on linux
Troubleshooting .net core on linux
Pavel Klimiankou
AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101
Timothy Spann
K. Tzoumas & S. Ewen – Flink Forward Keynote
K. Tzoumas & S. Ewen – Flink Forward Keynote
Flink Forward
Kernel Recipes 2013 - Viewing real time ltt trace using gtkwave
Kernel Recipes 2013 - Viewing real time ltt trace using gtkwave
Anne Nicolas
Security Monitoring with eBPF
Security Monitoring with eBPF
Alex Maestretti
Orion NTA Customer Training
Orion NTA Customer Training
SolarWinds
SNMP Monitoring at scale - Icinga Camp Milan 2023
SNMP Monitoring at scale - Icinga Camp Milan 2023
Icinga
LinuxCon 2015 Stateful NAT with OVS
LinuxCon 2015 Stateful NAT with OVS
Thomas Graf
Vpn ug5
Vpn ug5
Samsul Hoshi
FusionInventory at LSM/RMLL 2012
FusionInventory at LSM/RMLL 2012
Nouh Walid
More Related Content
Similar to Nft sync devel-pdf
Offloading Linux LAG Devices Via Open vSwitch and TC
Offloading Linux LAG Devices Via Open vSwitch and TC
Netronome
Open Source Monitoring Tools Shootout
Open Source Monitoring Tools Shootout
tomdc
Cfgmgmtcamp 2024 — eBPF-based Security Observability & Runtime Enforcement wi...
Cfgmgmtcamp 2024 — eBPF-based Security Observability & Runtime Enforcement wi...
Raphaël PINSON
Tcpdump hunter
Tcpdump hunter
Andrew McNicol
iptables 101- bottom-up
iptables 101- bottom-up
HungWei Chiu
Unifying Network Filtering Rules for the Linux Kernel with eBPF
Unifying Network Filtering Rules for the Linux Kernel with eBPF
Netronome
opensource Monitoring Tool , an overview
opensource Monitoring Tool , an overview
Kris Buytaert
OSMC 2008 | Monitoring Tools Shootout by Tom De Cooman
OSMC 2008 | Monitoring Tools Shootout by Tom De Cooman
NETWAYS
HPE NonStop GTUG Berlin - 'Yuma' Workshop
HPE NonStop GTUG Berlin - 'Yuma' Workshop
Thomas Burg
6-ZeroLab_decentralized_applications-2008.pptx
6-ZeroLab_decentralized_applications-2008.pptx
ClaudioTebaldi2
Troubleshooting .net core on linux
Troubleshooting .net core on linux
Pavel Klimiankou
AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101
Timothy Spann
K. Tzoumas & S. Ewen – Flink Forward Keynote
K. Tzoumas & S. Ewen – Flink Forward Keynote
Flink Forward
Kernel Recipes 2013 - Viewing real time ltt trace using gtkwave
Kernel Recipes 2013 - Viewing real time ltt trace using gtkwave
Anne Nicolas
Security Monitoring with eBPF
Security Monitoring with eBPF
Alex Maestretti
Orion NTA Customer Training
Orion NTA Customer Training
SolarWinds
SNMP Monitoring at scale - Icinga Camp Milan 2023
SNMP Monitoring at scale - Icinga Camp Milan 2023
Icinga
LinuxCon 2015 Stateful NAT with OVS
LinuxCon 2015 Stateful NAT with OVS
Thomas Graf
Vpn ug5
Vpn ug5
Samsul Hoshi
FusionInventory at LSM/RMLL 2012
FusionInventory at LSM/RMLL 2012
Nouh Walid
Similar to Nft sync devel-pdf
(20)
Offloading Linux LAG Devices Via Open vSwitch and TC
Offloading Linux LAG Devices Via Open vSwitch and TC
Open Source Monitoring Tools Shootout
Open Source Monitoring Tools Shootout
Cfgmgmtcamp 2024 — eBPF-based Security Observability & Runtime Enforcement wi...
Cfgmgmtcamp 2024 — eBPF-based Security Observability & Runtime Enforcement wi...
Tcpdump hunter
Tcpdump hunter
iptables 101- bottom-up
iptables 101- bottom-up
Unifying Network Filtering Rules for the Linux Kernel with eBPF
Unifying Network Filtering Rules for the Linux Kernel with eBPF
opensource Monitoring Tool , an overview
opensource Monitoring Tool , an overview
OSMC 2008 | Monitoring Tools Shootout by Tom De Cooman
OSMC 2008 | Monitoring Tools Shootout by Tom De Cooman
HPE NonStop GTUG Berlin - 'Yuma' Workshop
HPE NonStop GTUG Berlin - 'Yuma' Workshop
6-ZeroLab_decentralized_applications-2008.pptx
6-ZeroLab_decentralized_applications-2008.pptx
Troubleshooting .net core on linux
Troubleshooting .net core on linux
AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101
K. Tzoumas & S. Ewen – Flink Forward Keynote
K. Tzoumas & S. Ewen – Flink Forward Keynote
Kernel Recipes 2013 - Viewing real time ltt trace using gtkwave
Kernel Recipes 2013 - Viewing real time ltt trace using gtkwave
Security Monitoring with eBPF
Security Monitoring with eBPF
Orion NTA Customer Training
Orion NTA Customer Training
SNMP Monitoring at scale - Icinga Camp Milan 2023
SNMP Monitoring at scale - Icinga Camp Milan 2023
LinuxCon 2015 Stateful NAT with OVS
LinuxCon 2015 Stateful NAT with OVS
Vpn ug5
Vpn ug5
FusionInventory at LSM/RMLL 2012
FusionInventory at LSM/RMLL 2012
Nft sync devel-pdf
1.
nft-sync Distributing nftables rulesets
across the network Netfilter Workshop 2014 Montpelier, France Arturo Borrero Gonzalez arturo.borrero.glez@gmail.com
2.
nft-sync Main scenarios to
face: ● Cluster syncing ● Ruleset distribution (repository)
3.
nft-sync Cluster syncing
4.
nft-sync → Event handling →
Action
5.
nft-sync Ruleset distribution (repository)
6.
nft-sync → Ruleset reading →
Distribution fetch operation
7.
nft-sync Derivated scenarios: ● Remote
management ● Distributed policing
8.
nft-sync Remote management ● Network
service
9.
nft-sync
10.
nft-sync Distributed policing
11.
nft-sync → Basic config
file → Running modes: daemon, CLI → Operations: fetch, pull, sync, … How it works
12.
nft-sync → Simple sync
protocol (inspired by git) → XML / JSON (provided by libnftnl) → libev based How it works
13.
nft-sync The protocol: length 32
bits action fetch | pull | sync object <nftables>...</nftables>
14.
nft-sync iptables nftables Events reporting
no Yes XML / Json weak Yes Public library / API no Yes Built-in data sets no Yes iptables vs nftables
15.
nft-sync Conclusions: ● Just bootstraped
(May 2014) ● Proof of concept ● Initial work funded by nlnet and Google
16.
nft-sync Future works: ● Complete
all operations ● SSL-Based comunications ● Give flexibility, config options
17.
nft-sync Open issues: ● SSL
implementation ● Authtentication ● Ruleset mangling
18.
nft-sync More info: ● Announcement
by Netfilter Project http://marc.info/?l=netfilter&m=139991701024628&w=2 ● Source code http://git.netfilter.org/nft-sync/
19.
nft-sync Distributing nftables rulesets
across the network Netfilter Workshop 2014 Montpelier, France Arturo Borrero Gonzalez arturo.borrero.glez@gmail.com
Download now