{"id":5768,"date":"2019-12-07T08:48:35","date_gmt":"2019-12-06T23:48:35","guid":{"rendered":"http:\/\/mimumimu.net\/blog\/?p=5768"},"modified":"2019-12-07T08:48:35","modified_gmt":"2019-12-06T23:48:35","slug":"iptables-%e3%81%8b%e3%82%89-nftables-%e3%81%ab%e3%82%b5%e3%82%af%e3%83%83%e3%81%a8%e5%88%87%e3%82%8a%e6%9b%bf%e3%81%88%e3%82%8b","status":"publish","type":"post","link":"https:\/\/mimumimu.net\/blog\/2019\/12\/07\/iptables-%e3%81%8b%e3%82%89-nftables-%e3%81%ab%e3%82%b5%e3%82%af%e3%83%83%e3%81%a8%e5%88%87%e3%82%8a%e6%9b%bf%e3%81%88%e3%82%8b\/","title":{"rendered":"iptables \u304b\u3089 nftables \u306b\u30b5\u30af\u30c3\u3068\u5207\u308a\u66ff\u3048\u308b"},"content":{"rendered":"\n<p>\u3069\u3046\u3082\u307f\u3080\u3089\u3067\u3059\u3002<\/p>\n\n\n\n<p>Red Hat Enterprise Linux 8 \u306b\u306a\u3063\u3066 iptables \u304b\u3089 nftables \u306b\u672c\u683c\u7684\u306b\u5207\u308a\u66ff\u3048\u304c\u59cb\u307e\u308a\u307e\u3057\u305f\u3002<br>CentOS 8 \u3082\u3053\u308c\u3092\u53d7\u3051\u3066 nftables \u3078\u306e\u5207\u308a\u66ff\u3048\u304c\u5fc5\u8981\u306b\u306a\u3063\u3066\u304d\u307e\u3057\u305f\u3002<\/p>\n\n\n\n<p>\u53c2\u8003\u8cc7\u6599\uff1aLinux\u306b\u304a\u3051\u308b\u65b0\u305f\u306a\u30d1\u30b1\u30c3\u30c8\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u30c4\u30fc\u30eb\u300cnftables\u300d\u5165\u9580<br><a href=\"https:\/\/knowledge.sakura.ad.jp\/22636\/\">https:\/\/knowledge.sakura.ad.jp\/22636\/<\/a><\/p>\n\n\n\n<p>firewalld \u3067\u66f8\u3044\u3066\u3044\u308c\u3070\u5f71\u97ff\u3092\u53d7\u3051\u306a\u3044\u3089\u3057\u3044\u306e\u3067\u3059\u304c<br>iptables \u3067\u76f4\u63a5\u30eb\u30fc\u30eb\u3092\u66f8\u3044\u3066\u3044\u308b\u4eba\u306a\u306e\u3067\u3001\u3053\u308c\u3092\u6a5f\u306b nftables \u306b\u5909\u63db\u3057\u3066\u3057\u307e\u304a\u3046\u304b\u3068\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u5b9f\u306f\u3055\u304f\u3063\u3068\u5207\u308a\u66ff\u3048\u3089\u308c\u308b<\/h2>\n\n\n\n<p>\u3068\u308a\u3042\u3048\u305a\u5909\u63db\u3057\u3066 nftables \u3067\u7ba1\u7406\u51fa\u6765\u308b\u3088\u3046\u306b\u306a\u308c\u3070\u3088\u3044\u306e\u3067\u3042\u308c\u3070<br>\u4e0b\u8a18\u306e\uff12\u30d1\u30bf\u30fc\u30f3\u306e\u65b9\u6cd5\u3067\u5909\u63db\u53ef\u80fd\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u30d1\u30bf\u30fc\u30f31 : <strong>iptables-restore-translate \u3067\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u5909\u63db\u3059\u308b<\/strong><br>\u30d1\u30bf\u30fc\u30f32 : <strong>iptables \u3092\u6709\u52b9\u306b\u3057\u305f\u3042\u3068 nft \u3067\u8a2d\u5b9a\u3092\u53d6\u308a\u51fa\u3059<\/strong><\/p>\n\n\n\n<p>\u898b\u305f\u9650\u308a\u3067\u306f \u30d1\u30bf\u30fc\u30f3\uff11\u306e\u65b9\u304c\u8272\u3093\u306a\u30b5\u30a4\u30c8\u3067\u3082\u7d39\u4ecb\u3055\u308c\u3066\u304a\u308a<br>\u51fa\u3066\u304f\u308b\u8a2d\u5b9a\u3092\u898b\u3066\u3082\u7dba\u9e97\u306a\u8a2d\u5b9a\u306b\u601d\u3048\u308b\u306e\u3067\u3001\u63a8\u5968\u306a\u3093\u3060\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u305f\u3060\u30d1\u30bf\u30fc\u30f3\uff12\u3060\u3068\u3001NAT \u8a2d\u5b9a\u306a\u3069\u3082\u304d\u3061\u3093\u3068\u5909\u63db\u3055\u308c\u307e\u3059\u306e\u3067\u3001<br>\u6025\u304e\u3067\u884c\u3044\u305f\u3044\u5834\u5408\u306f\u30d1\u30bf\u30fc\u30f3\uff12\u3067\u3001<br>\u6642\u9593\u304c\u3042\u308b\u3068\u304d\u306f\uff11\u3067\u5909\u63db\u3057\u3066\u3001\u3055\u3089\u306b\u624b\u5165\u308c\u3092\u3059\u308b\u306e\u304c\u826f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">1. iptables-restore-translate \u3092\u4f7f\u3046<\/h2>\n\n\n\n<p>iptables \u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb (\/etc\/sysconfig\/iptables, \/etc\/sysconfig\/ip6tables) \u3084<br>iptables-save \u306e\u7d50\u679c\u3092\u7528\u3044\u3066\u5909\u63db\u3092\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"> 1.1. \u8a2d\u5b9a\u3092\u4fdd\u5b58\u3059\u308b <\/h3>\n\n\n\n<p>CentOS \u3084 RHEL \u3067 iptables \u3092\u76f4\u63a5\u89e6\u3063\u3066\u3044\u308b\u5834\u5408\u306f<br>\/etc\/sysconfig\/iptables \u3082\u3057\u304f\u306f \/etc\/sysconfig\/ip6tables \u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u3068\u601d\u3044\u307e\u3059\u306e\u3067<br>\u3053\u306e\u30b9\u30c6\u30c3\u30d7\u306f\u30b9\u30ad\u30c3\u30d7\u53ef\u80fd\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u305d\u3046\u3067\u306a\u3044\u3070\u3042\u3044\u3067 iptables \u306e\u8a2d\u5b9a\u3092\u53d6\u308a\u51fa\u3059\u5fc5\u8981\u304c\u3042\u308b\u5834\u5408\u306f<br>iptables-save \u30b3\u30de\u30f3\u30c9\u7b49\u3067\u53d6\u308a\u51fa\u3057\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.2. \u5909\u63db\u3059\u308b<\/h3>\n\n\n\n<p>\u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u7528\u3057\u3066 iptables \u306e\u8a2d\u5b9a\u3092 nftables \u306e\u30b3\u30de\u30f3\u30c9\u306b\u5909\u63db\u3057\u3066\u6d41\u3057\u8fbc\u307f\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># iptables-restore-translate -f \/etc\/sysconfig\/iptables   | nft -f - # IPv4\n# ip6tables-restore-translate -f \/etc\/sysconfig\/ip6tables | nft -f - # IPv6<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">1.3. \u4fdd\u5b58\u3059\u308b<\/h3>\n\n\n\n<p>\u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u4fdd\u5b58\u3057\u307e\u3059\u3002<br><br>\u306a\u304a\u4e0b\u8a18\u306e\u4fdd\u5b58\u5148\u306f RHEL, CentOS \u306e\u5834\u5408\u306e\u4f8b\u3067\u3059\u3002<br>\u304a\u4f7f\u3044\u306e\u30c7\u30a3\u30b9\u30c8\u30ea\u30d3\u30e5\u30fc\u30b7\u30e7\u30f3\u306b\u5408\u308f\u305b\u3066\u9069\u5b9c\u5909\u66f4\u3057\u3066\u304f\u3060\u3055\u3044<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># nft list ruleset > \/etc\/sysconfig\/nftables.conf<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>\u4ee5\u4e0a\u3067\u5909\u63db\u304c\u5b8c\u4e86\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u306e\u65b9\u6cd5\u3067\u5909\u63db\u3057\u305f\u5834\u5408\u3001\u4e0b\u8a18\u306e\u3088\u3046\u306a\u8a2d\u5b9a\u304c\u6d41\u3057\u8fbc\u307e\u308c\u307e\u3059\u3002<br>\uff08\u3042\u304f\u307e\u3067\u3082\u4e00\u4f8b\u3067\u3059\uff09<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/sysconfig\/iptables\n*filter\n:INPUT DROP &#91;0:0]\n:FORWARD DROP &#91;0:0]\n:OUTPUT ACCEPT &#91;0:0]\n-A INPUT -i lo -j ACCEPT\n-A INPUT -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT\n-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT\nCOMMIT\n\n# iptables-restore-translate -f \/etc\/sysconfig\/iptables\nadd table ip filter\nadd chain ip filter INPUT { type filter hook input priority 0; policy drop; }\nadd chain ip filter FORWARD { type filter hook forward priority 0; policy drop; }\nadd chain ip filter OUTPUT { type filter hook output priority 0; policy accept; }\nadd rule ip filter INPUT iifname \"lo\" counter accept\nadd rule ip filter INPUT ip protocol tcp ct state related,established  counter accept\nadd rule ip filter INPUT tcp dport 80 counter accept\n\n# nft list ruleset\ntable ip filter {\n        chain INPUT {\n                type filter hook input priority 0; policy drop;\n                iifname \"lo\" counter packets 0 bytes 0 accept\n                ip protocol tcp ct state established,related counter packets 0 bytes 0 accept\n                tcp dport http counter packets 0 bytes 0 accept\n        }\n\n        chain FORWARD {\n                type filter hook forward priority 0; policy drop;\n        }\n\n        chain OUTPUT {\n                type filter hook output priority 0; policy accept;\n        }\n}<\/code><\/pre>\n\n\n\n<p>\u307e\u305f\u8a66\u3057\u3066\u307f\u305f\u7bc4\u56f2\u3067\u306f\u3001NAT \u306e\u51e6\u7406\u304c\u4e0a\u624b\u304f\u5909\u63db\u3067\u304d\u306a\u3044\u3088\u3046\u3067<br>\u5931\u6557\u3059\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3057\u305f\u3002<\/p>\n\n\n\n<p>\u6b21\u306b\u7d39\u4ecb\u3059\u308b\u65b9\u6cd5\u3067\u306f\u3001\u30ea\u30b9\u30af\u304c\u5c11\u3057\u3042\u308b\u306e\u3067\u3059\u304c<br>\u4e0a\u624b\u304f\u5909\u63db\u3067\u304d\u307e\u3057\u305f\u306e\u3067\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">2. <strong>iptables \u3092\u6709\u52b9\u306b\u3057\u305f\u3042\u3068 nft \u3067\u8a2d\u5b9a\u3092\u53d6\u308a\u51fa\u3059<\/strong> <\/h2>\n\n\n\n<p>\u4eca\u307e\u3067\u4f7f\u7528\u3057\u3066\u3044\u305f\u8a2d\u5b9a\u3092 iptables \u30b3\u30de\u30f3\u30c9\u7d4c\u7531\u3067\u6709\u52b9\u306b\u3057\u305f\u3042\u3068<br>nft \u30b3\u30de\u30f3\u30c9\u3092\u7528\u3044\u3066\u73fe\u5728\u306e\u8a2d\u5b9a\u3092 nftables \u5f62\u5f0f\u3067\u53d6\u308a\u51fa\u3059\u65b9\u6cd5\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u306e\u65b9\u6cd5\u304c\u4f7f\u3048\u308b\u306e\u306f OS \u306b\u5165\u3063\u3066\u3044\u308b iptables \u30b3\u30de\u30f3\u30c9\u304c<br>nftables \u306e\u4e92\u63db\u30ec\u30a4\u30e4\u3092\u4f7f\u3063\u3066\u3044\u308b\u5834\u5408\u306b\u9650\u3089\u308c\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u4e92\u63db\u30ec\u30a4\u30e4\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u306b\u3064\u3044\u3066\u306f\u3001 &#8220;iptables &#8211;version&#8221; \u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057<br>\u672b\u5c3e\u306b (nf_tables) \u304c\u4ed8\u3044\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u3067\u5224\u65ad\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># CentOS 7 (iptables)\n# iptables --version\niptables v1.4.21\n\n# CentOS 8 (nftables)\n# iptables --version\niptables v1.8.2 (nf_tables)<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">2.1. iptables \u30b3\u30de\u30f3\u30c9\u7d4c\u7531\u3067\u8a2d\u5b9a\u3092\u6709\u52b9\u306b\u3059\u308b<\/h3>\n\n\n\n<p>iptables-restore \u30b3\u30de\u30f3\u30c9\u3092\u5229\u7528\u3057\u3066\u3001\u65e2\u5b58\u306e\u8a2d\u5b9a\u3092\u8aad\u307f\u8fbc\u307e\u305b\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># iptables-restore &lt; \/etc\/sysconfig\/iptables\n# ip6tables-restore &lt; \/etc\/sysconfig\/ip6tables<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">2.2. nft \u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3063\u3066\u8a2d\u5b9a\u3092\u8aad\u307f\u51fa\u3057\u3066\u4fdd\u5b58\u3059\u308b<\/h3>\n\n\n\n<p> \u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u4fdd\u5b58\u3057\u307e\u3059\u3002<br><br> \u306a\u304a\u4e0b\u8a18\u306e\u4fdd\u5b58\u5148\u306f RHEL, CentOS \u306e\u5834\u5408\u306e\u4f8b\u3067\u3059\u3002<br>\u304a\u4f7f\u3044\u306e\u30c7\u30a3\u30b9\u30c8\u30ea\u30d3\u30e5\u30fc\u30b7\u30e7\u30f3\u306b\u5408\u308f\u305b\u3066\u9069\u5b9c\u5909\u66f4\u3057\u3066\u304f\u3060\u3055\u3044  <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># nft list ruleset > \/etc\/sysconfig\/nftables.conf<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>\u4ee5\u4e0a\u3067\u5909\u63db\u304c\u5b8c\u4e86\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u306e\u65b9\u6cd5\u3067\u5909\u63db\u3057\u305f\u5834\u5408\u3001\u4e0b\u8a18\u306e\u3088\u3046\u306a\u8a2d\u5b9a\u304c\u6d41\u3057\u8fbc\u307e\u308c\u307e\u3059\u3002<br>\uff08\u3042\u304f\u307e\u3067\u3082\u4e00\u4f8b\u3067\u3059\uff09<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/sysconfig\/iptables\n*filter\n:INPUT DROP &#91;0:0]\n:FORWARD DROP &#91;0:0]\n:OUTPUT ACCEPT &#91;0:0]\n-A INPUT -i lo -j ACCEPT\n-A INPUT -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT\n-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT\nCOMMIT\n\n# nft list ruleset\ntable ip filter {\n        chain INPUT {\n                type filter hook input priority 0; policy drop;\n                iifname \"lo\" counter packets 0 bytes 0 accept\n                meta l4proto tcp ct state related,established counter packets 0 bytes 0 accept\n                meta l4proto tcp tcp dport 80 counter packets 0 bytes 0 accept\n        }\n\n        chain FORWARD {\n                type filter hook forward priority 0; policy drop;\n        }\n\n        chain OUTPUT {\n                type filter hook output priority 0; policy accept;\n        }\n}<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>\u5192\u982d\u3067\u66f8\u304d\u307e\u3057\u305f\u3088\u3046\u306b<br>iptables-restore-translate \u3092\u4f7f\u3063\u305f\u5834\u5408\u306e\u307b\u3046\u304c\u7dba\u9e97\u306a\u30b3\u30fc\u30c9\u304c\u751f\u6210\u3055\u308c\u308b\u3088\u3046\u3067\u3059\u306e\u3067<br>\u57fa\u672c\u7684\u306b\u306f\u3053\u306e\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u7528\u3057\u3066\u5909\u63db\u3057\u305f\u65b9\u304c\u826f\u3055\u305d\u3046\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u305f\u3060\u3001\u30a8\u30e9\u30fc\u304c\u51fa\u308b\u5834\u5408\u3082\u3042\u308a\u307e\u3059\u306e\u3067\u3001<br>\u304a\u4e92\u3044\u306e\u5909\u63db\u7d50\u679c\u3092\u898b\u306a\u304c\u3089\u3001\u624b\u3067\u66f8\u304d\u76f4\u3059\u3050\u3089\u3044\u304c\u4e00\u756a\u826f\u3044\u306e\u304b\u3082\u77e5\u308c\u307e\u305b\u3093\uff08\u82e6\u7b11\uff09<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">iptables \u306e\u30b3\u30de\u30f3\u30c9\u3092 nftables \u306e\u30b3\u30de\u30f3\u30c9\u306b\u5909\u63db\u3059\u308b<\/h2>\n\n\n\n<p>iptables \u30b3\u30de\u30f3\u30c9\u306e\u4ee3\u308f\u308a\u306b iptables-translate \u30b3\u30de\u30f3\u30c9\u3092\u7528\u3044\u308b\u4e8b\u3067<br>\u5909\u63db\u7d50\u679c\u3092\u5f97\u3089\u308c\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># iptables-translate -A INPUT -p tcp --dport 80 -j ACCEPT\nnft add rule ip filter INPUT tcp dport 80 counter accept<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>\u305d\u308c\u3067\u306f\u3088\u3044 nftables \u30e9\u30a4\u30d5\u3092\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u3069\u3046\u3082\u307f\u3080\u3089\u3067\u3059\u3002 Red Hat Enterprise Linux 8 \u306b\u306a\u3063\u3066 iptables \u304b\u3089 nftables \u306b\u672c\u683c\u7684\u306b\u5207\u308a\u66ff\u3048\u304c\u59cb\u307e\u308a\u307e\u3057\u305f\u3002CentOS 8 \u3082\u3053\u308c\u3092\u53d7\u3051\u3066 nftables \u3078\u306e\u5207\u308a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5768","post","type-post","status-publish","format-standard","hentry","category-other"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts\/5768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/comments?post=5768"}],"version-history":[{"count":0,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/posts\/5768\/revisions"}],"wp:attachment":[{"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/media?parent=5768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/categories?post=5768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mimumimu.net\/blog\/wp-json\/wp\/v2\/tags?post=5768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}