Get the latest tech news

Faster Firewalls with Bpfilter


From servers in a data center to desktop computers, many devices communicating on a network wi [...]

In 2018, Alexei Starovoitov, Daniel Borkmann, and David S. Miller proposed bpfilter as a way to transparently increase iptables performance by translating the filtering rules into BPF programs directly in the kernel ... sort of. Eventually, in early 2023, Starovoitov and I decided to make bpfilter a freestanding project, removing the user-mode helper from the kernel source tree. bfcli was created as a way to easily communicate with the daemon, so new features can be tested quickly without the requirement for a dedicated translation layer.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Bpfilter

Bpfilter

Photo of Faster Firewalls

Faster Firewalls