BPF comes to firewalls
BPF comes to firewalls
Posted Feb 20, 2018 4:35 UTC (Tue) by eahay (guest, #110720)Parent article: BPF comes to firewalls
Posted Feb 20, 2018 6:46 UTC (Tue)
by kay (guest, #1362)
[Link]
Posted Feb 20, 2018 12:19 UTC (Tue)
by bernat (subscriber, #51658)
[Link] (1 responses)
Posted Feb 24, 2018 20:07 UTC (Sat)
by kleptog (subscriber, #1183)
[Link]
In any case, if we do firewall rules as BPF we end up with the same problem surely? The performance improvement would be that you can pass your firewall through an compiler/optimiser to make it more efficient, but as a side effect you end up with the same problem, namely, to update a single rule you need to replace the whole program. Only now you've added an optimise step in between.
Unless you change your API to transactional one where you can send updates and get a confirmation asynchronously and the backend is smart enough to avoid actually updating the kernel for every change.
Posted Apr 19, 2018 2:26 UTC (Thu)
by manhnt (guest, #123784)
[Link] (2 responses)
Posted Aug 13, 2018 4:07 UTC (Mon)
by fest3er (guest, #60379)
[Link]
Posted Aug 13, 2018 16:37 UTC (Mon)
by antiphase (subscriber, #111993)
[Link]
BPF comes to firewalls
BPF comes to firewalls
BPF comes to firewalls
BPF comes to firewalls
BPF comes to firewalls
BPF comes to firewalls
