gSpotx2f / ruantiblock_openwrt

Обход блокировок в OpenWrt с помощью Tor или VPN
GNU General Public License v3.0
204 stars 19 forks source link

iptables vs nftables #19

Closed vaalberith closed 1 year ago

vaalberith commented 1 year ago

Greetings!

Is there any possibility for You to migrate this awesome project from iptables to nftables since iptables is treatead like legacy on fresh OpenWRT firmware? Some people guess that there could be some priority conflicts while using openwrt-provided nftables and iptables/iptables-legacy. Also, nftables seems to have better perfomance? More to say, duplicating (i mean installing both) such important subsystems is doubtfull.

Thank You for Your work and best wishes, comrade!

gSpotx2f commented 1 year ago

В данный момент это невозможно, потому что dnsmasq в OpenWrt 22.03 не поддерживает nftables. Кроме того, nftables (именно утилита nft) имеет проблемы с большими сетами IP адресов (десятки тысяч записей): тормоза, жуткие утечки памяти при манипуляциях с сетами и правилами.