public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* Enable eBPF XDP/TC kernel feature for IPFire
@ 2024-04-09 17:36 Vincent Li
  2024-04-10  9:04 ` Adolf Belka
  0 siblings, 1 reply; 14+ messages in thread
From: Vincent Li @ 2024-04-09 17:36 UTC (permalink / raw)
  To: development

[-- Attachment #1: Type: text/plain, Size: 688 bytes --]

Hi,

I have been working on enabling eBPF XDP/TC kernel feature for IPFire,
please refer to
https://upload.wikimedia.org/wikipedia/commons/3/37/Netfilter-packet-flow.svg
for where XDP fit in Linux network datapath, XDP will not interfere
with existing IPFire firewall rules. XDP is especially good at DDoS
packet filtering at high speed, see
https://netdevconf.info/0x15/slides/30/Netdev%200x15%20Accelerating%20synproxy%20with%20XDP.pdf

I think we only need to enable XDP/TC network filtering capability
without eBPF tracing capability which some users are concerned about
potential host security information leaks.

Please let me know what you think, thanks!

Vincent

^ permalink raw reply	[flat|nested] 14+ messages in thread
[parent not found: <CAK3+h2x_Qx3DtbKGPEexfjfEeoEJVnNhOxZGJMkSMYJZW=qhMg@mail.gmail.com>]

end of thread, other threads:[~2024-04-25 10:08 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-04-09 17:36 Enable eBPF XDP/TC kernel feature for IPFire Vincent Li
2024-04-10  9:04 ` Adolf Belka
2024-04-10 14:11   ` Vincent Li
2024-04-10 15:17     ` Peter Müller
2024-04-10 18:01       ` Vincent Li
2024-04-17 16:07         ` Michael Tremer
2024-04-17 22:36           ` Vincent Li
2024-04-17 22:41             ` Vincent Li
2024-04-18  8:57             ` Michael Tremer
2024-04-18 15:21               ` Vincent Li
2024-04-18 21:13                 ` Michael Tremer
2024-04-19  0:17                   ` Vincent Li
2024-04-24 15:28                     ` Michael Tremer
     [not found] <CAK3+h2x_Qx3DtbKGPEexfjfEeoEJVnNhOxZGJMkSMYJZW=qhMg@mail.gmail.com>
2024-04-25 10:08 ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox