本页介绍如何从旧式 iptables/xtables(legacy)体系迁移到新的 nftables 框架。
常见需求是将现有的 iptables 规则集迁移到 nftables。Netfilter 团队提供了一些工具和机制,让迁移更容易。
请务必阅读以下相关页面:
迁移完成后,建议进一步采用 nftables 的新机制,例如集合、映射、裁决映射、连接等。
命令转换
可以转换 iptables/ip6tables 命令,以了解等价的 nftables 写法:
% iptables-translate -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
nft add rule ip filter INPUT tcp dport 22 ct state new counter accept
% ip6tables-translate -A FORWARD -i eth0 -o eth3 -p udp -m multiport --dports 111,222 -j ACCEPT
nft add rule ip6 filter FORWARD iifname eth0 oifname eth3 meta l4proto udp udp dport { 111,222} counter accept
除了逐条转换命令,也可以一次转换整个规则集:
% iptables-save > save.txt
% cat save.txt
# Generated by iptables-save v1.6.0 on Sat Dec 24 14:26:40 2016
*filter
:INPUT ACCEPT [5166:1752111]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [5058:628693]
-A FORWARD -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
COMMIT
# Completed on Sat Dec 24 14:26:40 2016
% iptables-restore-translate -f save.txt
# Translated by iptables-restore-translate v1.6.0 on Sat Dec 24 14:26:59 2016
add table ip filter
add chain ip filter INPUT { type filter hook input priority 0; }
add chain ip filter FORWARD { type filter hook forward priority 0; }
add chain ip filter OUTPUT { type filter hook output priority 0; }
add rule ip filter FORWARD tcp dport 22 ct state new counter accept
转换结果可以直接交给 nftables:
% iptables-restore-translate -f save.txt > ruleset.nft
% nft -f ruleset.nft
% nft list ruleset
table ip filter {
chain INPUT {
type filter hook input priority 0; policy accept;
}
chain FORWARD {
type filter hook forward priority 0; policy accept;
tcp dport ssh ct state new counter packets 0 bytes 0 accept
}
chain OUTPUT {
type filter hook output priority 0; policy accept;
}
}
这些转换工具包含在 iptables 源码压缩包中,同时支持 iptables 和 ip6tables。
使用 nf_tables 兼容后端
自 2018 年 6 月起,旧式 xtables/setsockopt 工具被视为 legacy。
不过,仍然支持通过 iptables、ip6tables、arptables、ebtables 的旧语法,使用内核的 nf_tables 后端。
详细说明见 Legacy xtables tools。
% iptables-nft -A FORWARD -p icmp -j ACCEPT
% iptables-nft-save
# Generated by xtables-save v1.6.0 (nf_tables) on Sat Dec 24 14:38:08 2016
*filter
:INPUT ACCEPT [62:3777]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [62:4074]
-A FORWARD -p icmp -j ACCEPT
COMMIT
# Completed on Sat Dec 24 14:38:08 2016
% nft list ruleset
table ip filter {
chain INPUT {
type filter hook input priority 0; policy accept;
}
chain FORWARD {
type filter hook forward priority 0; policy accept;
ip protocol icmp counter packets 0 bytes 0 accept
}
chain OUTPUT {
type filter hook output priority 0; policy accept;
}
}
注意:只要存在对应转换,就会转换为原生 nftables 语法。
如果某些功能缺少转换,nftables 中就会显示带注释的规则:
% ebtables-nft -L
Bridge table: filter
Bridge chain: INPUT, entries: 0, policy: ACCEPT
Bridge chain: FORWARD, entries: 2, policy: ACCEPT
--802_3-type 0x0001 -j CONTINUE
--mark 0x1 -j CONTINUE
Bridge chain: OUTPUT, entries: 0, policy: ACCEPT
% nft list ruleset
table bridge filter {
chain INPUT {
type filter hook input priority -200; policy accept;
}
chain FORWARD {
type filter hook forward priority -200; policy accept;
#--802_3-type 0x0001 counter packets 0 bytes 0
#--mark 0x1 counter packets 0 bytes 0
}
chain OUTPUT {
type filter hook output priority -200; policy accept;
}
}
使用这些工具时,一种迁移流程是先保存旧的 iptables-legacy 规则集,再通过 iptables-nft 加载:
% iptables-save > iptables.txt
% iptables-nft-restore < iptables.txt
% iptables-nft-save
# Generated by xtables-save v1.6.0 (nf_tables) on Sat Dec 24 14:51:41 2016
*filter
:INPUT ACCEPT [19:1283]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [18:2487]
-A FORWARD -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
COMMIT
# Completed on Sat Dec 24 14:51:41 2016
% nft list ruleset
table ip filter {
chain INPUT {
type filter hook input priority 0; policy accept;
}
chain FORWARD {
type filter hook forward priority 0; policy accept;
ip protocol tcp tcp dport 22 ct state new counter packets 0 bytes 0 accept
}
chain OUTPUT {
type filter hook output priority 0; policy accept;
}
}
警告:应谨慎同时使用 nft 与 legacy 工具。这样意味着同时使用内核的 x_tables 和 nf_tables 子系统,可能产生意料之外的结果。
另请参阅
原文对应修订版本 677,最后编辑时间为 2021 年 2 月 12 日 10:53。
原文:Moving from iptables to nftables。作者/维护方:nftables wiki / Netfilter 社区。本文为中文翻译,代码及命令保留原文。
除非另有说明,原文内容按 GNU Free Documentation License 1.3 或更新版本提供。











暂无评论内容