netfilter project logo

News of the netfilter/iptables project

News & Announcements

2020-04-01

conntrack-tools 1.4.6 released

The Netfilter Core Team has released conntrack-tools-1.4.6.

2020-04-01

libnetfilter_conntrack 1.0.8 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.8.

2020-04-01

nftables 0.9.4 released

The Netfilter Core Team has released nftables-0.9.4.

2020-04-01

libnftnl 1.1.6 released

The Netfilter Core Team has released libnftnl-1.1.6.

2019-12-02

nftables 0.9.3 released

The Netfilter Core Team has released nftables-0.9.3.

2019-12-02

iptables 1.8.4 released

The Netfilter Core Team has released iptables-1.8.4.

2019-12-02

ebtables 2.0.11 released

The Netfilter Core Team has released ebtables-2.0.11.

2019-12-02

arptables 0.0.5 released

The Netfilter Core Team has released arptables-0.0.5.

2019-12-02

libnftnl 1.1.5 released

The Netfilter Core Team has released libnftnl-1.1.5.

2019-08-19

nftables 0.9.2 released

The Netfilter Core Team has released nftables-0.9.2.

2019-08-19

libnftnl 1.1.4 released

The Netfilter Core Team has released libnftnl-1.1.4.

2003-07-16

New coreteam member: Phil Sutter

The netfilter core team has invited Phil to join the coreteam. Phil is a dedicated member of the Netfilter development community who has already been responsible for recent updates in the iptables and the nftables userspace codebase.

2019-06-24

nftables 0.9.1 released

The Netfilter Core Team has released nftables-0.9.1.

2019-05-27

iptables 1.8.3 released

The Netfilter Core Team has released iptables-1.8.3.

2019-05-27

libnftnl 1.1.3 released

The Netfilter Core Team has released libnftnl-1.1.3.

2018-11-13

libnftnl 1.1.2 released

The Netfilter Core Team has released libnftnl-1.1.2.

2018-11-13

iptables 1.8.2 released

The Netfilter Core Team has released iptables-1.8.2.

2018-10-23

iptables 1.8.1 released

The Netfilter Core Team has released iptables-1.8.1.

2018-07-07

iptables 1.8.0 released

The Netfilter Core Team has released iptables-1.8.0.

2018-06-08

nftables 0.9.0 released

The Netfilter Core Team has released nftables-0.9.0.

2018-06-08

libnftnl 1.1.1 released

The Netfilter Core Team has released libnftnl-1.1.1.

2018-05-10

nftables 0.8.5 released

The Netfilter Core Team has released nftables-0.8.5.

2018-05-01

conntrack-tools 1.4.5 released

The Netfilter Core Team has released conntrack-tools-1.4.5.

2018-05-01

libnetfilter_conntrack 1.0.7 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.7.

2018-05-01

nftables 0.8.4 released

The Netfilter Core Team has released nftables-0.8.4.

2018-05-01

libnftnl 1.1.0 released

The Netfilter Core Team has released libnftnl-1.1.0.

2018-04-27

ulogd 2.0.7 released

The Netfilter Core Team has released ulogd-2.0.7.

2018-03-03

nftables 0.8.3 released

The Netfilter Core Team has released nftables-0.8.3.

2018-02-02

nftables 0.8.2 released

The Netfilter Core Team has released nftables-0.8.2.

2018-02-02

iptables 1.6.2 released

The Netfilter Core Team has released iptables-1.6.2.

2018-01-15

nftables 0.8.1 released

The Netfilter Core Team has released nftables-0.8.1.

2018-01-02

libnftnl 1.0.9 released

The Netfilter Core Team has released libnftnl-1.0.9.

2017-11-13

libnetfilter_queue 1.0.3 released

The Netfilter Core Team has released libnetfilter_queue-1.0.3.

2017-10-13

nftables 0.8 released

The Netfilter Core Team has released nftables-0.8.

2017-10-13

libnftnl 1.0.8 released

The Netfilter Core Team has released libnftnl-1.0.8.

2017-01-27

iptables 1.6.1 released

The Netfilter Core Team has released iptables-1.6.1.

2016-Dec-20

nftables 0.7

The Netfilter Core Team has released nftables-0.7. See announcement for more information.

2016-Dec-19

libnftnl 1.0.7 released

The Netfilter Core Team has released libnftnl-1.0.7. See announcement for more information.

2016-Aug-22

nfacct 1.0.2 released

The Netfilter Core Team has released nfacct-1.0.2. This includes the quota support available since Linux kernel >= 3.16.

2016-Aug-22

libnetfilter_acct 1.0.3 released

The Netfilter Core Team has released libnetfilter_acct-1.0.3. This release contains the quota support available in the Linux kernel >= 3.16.

2016-Aug-22

conntrack-tools 1.4.4 released

The Netfilter Core Team has released conntrack-tools-1.4.4. This release includes NAT IPv6 support for state synchronization, list filtering with address masks, a new conntrackd.conf manpage, initial systemd integration and other minor documentation updates.

2016-Aug-22

libnetfilter_conntrack 1.0.6 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.6. This release includes NAT IPv6 support, the new nfct_labels_get_path() interface, zones both for original and reply tuples and clang build fixes.

2016-Jul-02

libmnl 1.0.4 released

The Netfilter Core Team has released libmnl-1.0.4.

2016-Jun-29

Statement of netfilter project on GPL enforcement

The netfilter project has released a public statement on GPL enforcement that is available by clicking here.

2016-Jun-02

nftables 0.6

The Netfilter Core Team has released nftables-0.6.

2016-May-30

libnftnl 1.0.6 released

The Netfilter Core Team has released libnftnl-1.0.6.

2015-Dec-18

iptables 1.6.0 released

The Netfilter Core Team has released iptables-1.6.0. This release includes the first release of the iptables over nftables compatibility tools, accumulated fixes and enhancements.

2015-Nov-22

New PGP key

The Netfilter Core Team has generated a new PGP key since the old one expired. We use this key to sign our software releases. For more information, please visit the PGP section in this homepage.

2015-Sep-17

nftables 0.5

The Netfilter Core Team has released nftables-0.5.

2015-Sep-17

libnftnl 1.0.5 released

The Netfilter Core Team has released libnftnl-1.0.5, to resolve LIBVERSION and symbol versioning problems with the previous release.

2015-Sep-16

libnftnl 1.0.4 released

The Netfilter Core Team has released libnftnl-1.0.4.

2015-Sep-08

conntrack-tools 1.4.3 released

The Netfilter Core Team has released conntrack-tools-1.4.3. This release includes accumulated bugfixes.

2015-Sep-08

libnetfilter_conntrack 1.0.5 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.5. This release includes accumulated bugfixes.

2015-May-01

ulogd 2.0.5 released

The Netfilter Core Team has released ulogd-2.0.5.

2014-Dec-16

nftables 0.4

The Netfilter Core Team has released nftables-0.4.

2014-Dec-16

libnftnl 1.0.3 released

The Netfilter Core Team has released libnftnl-1.0.3.

2014-Jun-26

nftables 0.3

The Netfilter Core Team has released nftables-0.3.

2014-Jun-25

libnftnl 1.0.2 released

The Netfilter Core Team has released libnftnl-1.0.2.

2014-Apr-17

libnftnl 1.0.1 released

The Netfilter Core Team has released libnftnl-1.0.1.

2014-Apr-14

nftables 0.2

The Netfilter Core Team has released nftables-0.2.

2014-Mar-23

ulogd 2.0.4 released

The Netfilter Core Team has released ulogd-2.0.4. This release includes JSON output and bugfixes.

2014-Jan-20

nftables 0.099

The Netfilter Core Team has released nftables-0.099.

2014-Jan-20

libnftnl 1.0.0 released

The Netfilter Core Team has released libnftnl-1.0.0.

2013-Nov-22

iptables 1.4.21 released

The Netfilter Core Team has released iptables-1.4.21.

2013-Nov-19

ulogd 2.0.3 released

The Netfilter Core Team has released ulogd-2.0.3. This release includes improved support for database output and bugfixes.

2013-Aug-06

conntrack-tools 1.4.2 released

The Netfilter Core Team has released conntrack-tools-1.4.2. This release includes bugfixes and the connlabel support.

2013-Aug-06

iptables 1.4.20 released

The Netfilter Core Team has released iptables-1.4.20.

2013-Aug-06

libnetfilter_conntrack 1.0.4 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.4.

2013-May-29

iptables 1.4.19.1 released

The Netfilter Core Team has released iptables-1.4.19.1.

2013-May-29

iptables 1.4.19 released

The Netfilter Core Team has released iptables-1.4.19.

2013-Mar-04

libnetfilter_conntrack 1.0.3 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.3.

2013-Mar-03

iptables 1.4.18 released

The Netfilter Core Team has released iptables-1.4.18.

2013-Mar-03

ulogd 2.0.2 released

The Netfilter Core Team has released ulogd-2.0.2. This release includes support for the graphite output and bugfixes.

2013-Mar-03

nfacct 1.0.1 released

The Netfilter Core Team has released nfacct-1.0.1. This release includes a new command to restore counters.

2013-Mar-03

conntrack-tools 1.4.1 released

The Netfilter Core Team has released conntrack-tools-1.4.1. This release includes one bugfix for conntrackd.

2013-Mar-03

libnetfilter_acct 1.0.2 released

The Netfilter Core Team has released libnetfilter_acct-1.0.2.

2012-Dec-25

iptables 1.4.17 released

The Netfilter Core Team has released iptables-1.4.17.

2012-Oct-30

New ulogd2 maintainer

We are happy to announce that our Netfilter core team fellow Eric Leblond has become the official maintainer of ulogd.

2012-Oct-25

Netfilter core team updates

The Netfilter Core Team has been updated. We have to welcome new fellow hackers Eric Leblond and Florian Westphal. They have been invited to join us for their longstanding contributions to the Netfilter codebase. On the other hand, we have to say a big thank you to Harald Welte, Martin Josefsson and Yasuyuki Kozakai who have now entered the exclusive status of Emeritus core team members.

2012-Oct-18

iptables 1.4.16.3 released

The Netfilter Core Team has released iptables-1.4.16.3.

2012-Oct-09

libnetfilter_acct 1.0.1 released

The Netfilter Core Team has released libnetfilter_acct-1.0.1.

2012-Oct-08

libnetfilter_cthelper 1.0.0 released

The Netfilter Core Team has released libnetfilter_cthelper-1.0.0.

2012-Oct-08

ulogd 2.0.1 released

The Netfilter Core Team has released ulogd-2.0.1. This release includes support for the nfacct infrastructure (available since Linux kernel 3.4).

2012-Oct-08

conntrack-tools 1.4.0 released

The Netfilter Core Team has released conntrack-tools-1.4.0. This release adds the new user-space helper infrastructure plus the NFSv3 and Oracle*TNS helpers. This requires a Linux kernel >= 3.6.

2012-Oct-08

libnetfilter_queue 1.0.2 released

The Netfilter Core Team has released libnetfilter_queue-1.0.2.

2012-Oct-08

libnetfilter_conntrack 1.0.2 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.2.

2012-Oct-08

libnfnetlink 1.0.1 released

The Netfilter Core Team has released libnfnetlink-1.0.1.

2012-Oct-08

iptables 1.4.16.2 released

The Netfilter Core Team has released iptables-1.4.16.2.

2012-Oct-08

iptables 1.4.16.1 released

The Netfilter Core Team has released iptables-1.4.16.1.

2012-Oct-08

iptables 1.4.16 released

The Netfilter Core Team has released iptables-1.4.16.

2012-Jul-31

conntrack-tools 1.2.2 released

The Netfilter Core Team has released conntrack-tools-1.2.2. This release contains bugfixes.

2012-Jul-31

iptables 1.4.15 released

The Netfilter Core Team has released iptables-1.4.15. This release includes support for new features added to Linux kernel 3.5 and one major bugfix if gcc-4.7 is used.

2012-Jun-17

ulogd 2.0.0 released

By popular demand, the Netfilter Core Team has released ulogd-2.0.0. Series 1.x has entered end-of-life. Any development effort will be targeted to 2.x series. Please, upgrade to 2.x.

2012-May-26

conntrack-tools 1.2.1 released

The Netfilter Core Team has released conntrack-tools-1.2.1. It fixes compilation issue with 1.2.0.

2012-May-26

libmnl 1.0.3 released

The Netfilter Core Team has released libmnl-1.0.3.

2012-May-26

iptables 1.4.14 released

The Netfilter Core Team has released iptables-1.4.14.

2012-May-26

conntrack-tools 1.2.0 released

The Netfilter Core Team has released conntrack-tools-1.2.0. This release includes the support for expectation synchronization and the new nfct tool (to be used with the new cttimeout infrastructure available since Linux kernel 3.4.0).

2012-May-26

libnetfilter_cttimeout 1.0.0 released

The Netfilter Core Team has released libnetfilter_cttimeout-1.0.0.

2012-May-18

libnetfilter_conntrack 1.0.1 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.1. This update contains important improvements for the expectation support.

2012-Apr-03

Secure use of iptables and connection tracking helpers

Eric Leblond has published an interesting article on the secure use of the Connection Tracking helpers in his blog.

2012-Mar-27

iptables 1.4.13 released

The Netfilter Core Team has released iptables-1.4.13.

2012-Mar-27

nfacct 1.0.0 released

The Netfilter Core Team has released nfacct-1.0.0.

2012-Mar-27

libnetfilter_acct 1.0.0 released

The Netfilter Core Team has released libnetfilter_acct-1.0.0.

2012-Jan-04

conntrack-tools 1.0.1 released

The Netfilter Core Team has released conntrack-tools-1.0.1.

2012-Jan-04

libnetfilter_conntrack 1.0.0 released

The Netfilter Core Team has released libnetfilter_conntrack-1.0.0.

2012-Jan-02

libnetfilter_log 1.0.1 released

The Netfilter Core Team has released libnetfilter_log-1.0.1.

2012-Jan-02

libnetfilter_queue 1.0.1 released

The Netfilter Core Team has released libnetfilter_queue-1.0.1.

2012-Jan-02

libmnl 1.0.2 released

The Netfilter Core Team has released libmnl-1.0.2.

2012-Jan-02

iptables 1.4.12.2 released

The Netfilter Core Team has released iptables-1.4.12.2.

2011-Sep-01

iptables 1.4.12.1 released

The Netfilter Core Team has released iptables-1.4.12.1.

2011-Aug-27

New PGP key

The Netfilter Core Team has generated a new PGP key since the old one expired. We use this key to sign our software releases. For further information, please visit the PGP section in this homepage.

2011-Jul-22

iptables 1.4.12 released

The Netfilter Core Team has released iptables-1.4.12.

2011-Jun-08

iptables 1.4.11.1 released

The Netfilter Core Team has released iptables-1.4.11.1.

2011-May-26

iptables 1.4.11 released

The Netfilter Core Team has released iptables-1.4.11.

2011-02-27

conntrack-tools 1.0.0 released

The Netfilter Core Team has released conntrack-tools-1.0.0.

2011-Feb-24

libnetfilter_conntrack 0.9.1 released

The Netfilter Core Team has released libnetfilter_conntrack-0.9.1.

2010-Dec-26

libmnl 1.0.1 released

The Netfilter Core Team has released libmnl-1.0.1.

2010-Dec-17

libmnl 1.0.0 released

The Netfilter Core Team has released libmnl-1.0.0.

2010-Oct-29

iptables 1.4.10 released

The Netfilter Core Team has released iptables-1.4.10.

2010-Sep-08

libnetfilter_conntrack 0.9.0 released

The Netfilter Core Team has released libnetfilter_conntrack-0.9.0.

2010-Aug-06

iptables 1.4.9.1 released

The Netfilter Core Team has released iptables-1.4.9.1.

2010-Aug-03

iptables 1.4.9 released

The Netfilter Core Team has released iptables-1.4.9.

2010-Jul-16

ulogd 2.0.0beta4 released

The Netfilter Core Team has released ulogd 2.0.0beta4.

2010-07-15

conntrack-tools 0.9.15 released

The Netfilter Core Team has released conntrack-tools-0.9.15.

2010-Jul-15

libnetfilter_conntrack 0.0.102 released

The Netfilter Core Team has released libnetfilter_conntrack-0.0.102.

2010-Jul-15

libnetfilter_log 1.0.0 released

The Netfilter Core Team has released libnetfilter_log-1.0.0.

2010-Jul-11

libnetfilter_queue 1.0.0 released

The Netfilter Core Team has released libnetfilter_queue-1.0.0.

2010-May-20

iptables 1.4.8 released

The Netfilter Core Team has released iptables-1.4.8.

2010-Mar-01

iptables 1.4.7 released

The Netfilter Core Team has released iptables-1.4.7.

2009-Dec-28

conntrack-tools 0.9.14 released

The Netfilter Core Team has released conntrack-tools-0.9.14.

2009-Dec-23

libnetfilter_conntrack 0.0.101 released

The Netfilter Core Team has released libnetfilter_conntrack-0.0.101.

2009-Dec-09

iptables 1.4.6 released

The Netfilter Core Team has released iptables-1.4.6.

2009-Sep-14

iptables 1.4.5 released

The Netfilter Core Team has released iptables-1.4.5.

2009-Jul-17

conntrack-tools 0.9.13 released

The Netfilter Core Team has released conntrack-tools-0.9.13. With regards to the command line tool, this release includes support for all the protocol helpers available in 2.6.30 that were missing so far (SCTP, UDPlite, DCCP and GRE). The daemon updates includes a fix for a memory leak that can be triggered under heavy load and if you set a hashtable in user-space that is smaller than the one in the kernel. Moreover, it adds initial support for DCCP and SCTP state-synchronization.

2009-Jul-16

libnetfilter_conntrack 0.0.100 released

The Netfilter Core Team has released libnetfilter_conntrack-0.0.100.

2009-Jun-22

libnfnetlink 1.0.0 released

The Netfilter Core Team has released libnfnetlink-1.0.0.

2009-Jun-16

iptables 1.4.4 released

The Netfilter Core Team has released iptables-1.4.4.

2009-Apr-06

iptables 1.4.3.2 released

The Netfilter Core Team has released iptables-1.4.3.2 which contains accumulated bugfixes.

2009-Apr-01

conntrack-tools 0.9.12 released

The Netfilter Core Team has released conntrack-tools-0.9.12 that includes a new `-S' option for the command line tool and a generic infrastructure to allow using different protocols to replicate state-changes, currently unicast UDP and multicast are supported.

2009-Mar-24

iptables 1.4.3.1 released

The Netfilter Core Team has released iptables-1.4.3.1 which fixes compilation problems in 1.4.3 and a couple of minor issues.

2009-Mar-23

iptables 1.4.3 released

The Netfilter Core Team has released iptables-1.4.3.

2009-Mar-18

initial nftables release

Patrick McHardy has released nftables which is the intended successor of iptables. The project is still in alpha stage. You can get more info in this link.

2009-Mar-06

ulogd 2.0.0beta3 released

The Netfilter Core Team has released ulogd 2.0.0beta3. This is another development release of ulogd2, the re-incarnation of ulogd2 that includes flow and packet accounting capabilities. This release includes accumulated fixes.

2009-Mar-06

ipset 2.5.0 release

ipset 2.5.0 has been released.

2009-Mar-06

libnfnetlink 0.0.41, libnetfilter_queue 0.0.17 and libnetfilter_log 0.0.16 releases

The Netfilter Core Team has released several library updates:

This release set includes accumulated fixes.

2009-Feb-21

conntrack-tools 0.9.11 released

The Netfilter Core Team has released conntrack-tools-0.9.11 that includes accumulated fixes, one improvement for the polling approach and a couple of new features.

2009-Feb-11

ipset 2.4.8 release

ipset 2.4.8 has been released. This release contains one bugfix for hash-sets, the use of the new Jenkins' hash function for better performance and a couple of minor compilation fixes.

2009-Jan-29

ipset 2.4.7 release

ipset 2.4.7 has been released. This release contains a compatibility fix for Linux kernels >= 2.6.28 and minor cleanup. There is no need to upgrade unless you want to use recent Linux kernels.

2009-Jan-25

conntrack-tools 0.9.10 released

The Netfilter Core Team has released conntrack-tools-0.9.10. This release includes fixes, improvements; and new features like the new statistics options, multi-dedicated link support and polling (or batch-based) support for conntrackd; and the `-C' option for the command line interface to display the number of entries in the state and expectation tables. Feedback is welcome!

2009-01-21

ipset tree moves to git

The ipset tree has moved to the Netfilter's git tree, the former subversion repository will not be updated any longer. Please, update your bookmarks.

2009-01-14

libnfnetlink 0.0.40 released

The Netfilter Core Team has released libnfnetlink-0.0.40. This release includes a couple of updates and one fix for the interface2index infrastructure.

2008-Dec-18

conntrack-tools 0.9.9 released

The Netfilter Core Team has released conntrack-tools-0.9.9. This release includes tons of updates, fixes and improvements. Upgrade is recommended.

2008-Dec-14

libnetfilter_conntrack release

The netfilter core team has released libnetfilter_conntrack-0.0.99 that includes couple of minor fixes.

2008-Nov-29

libnetfilter_conntrack release

The netfilter core team has released libnetfilter_conntrack-0.0.98 that includes one major fix, a couple of minor fixes, the new attribute group API and cleanups.

2008-Oct-21

conntrack-tools 0.9.8 released

The Netfilter Core Team has released conntrack-tools-0.9.8. This release includes tons of updates, fixes and improvements in the command line tool and the user-space daemon. Upgrade is recommended.

2008-Oct-13

iptables 1.4.2 released

The Netfilter Core Team has released iptables-1.4.2.

The Netfilter Core Team has also released libnetfilter_conntrack-0.0.97 that includes minor fixes, some enhancements and cleanups.

2008-Aug-15

ulogd 2.0.0beta2 released

The Netfilter Core Team has released ulogd 2.0.0beta2. This is another development release of ulogd2, the re-incarnation of ulogd2 that includes flow and packet accounting capabilities. This release includes major improvements and fixes. We have also released libnetfilter_log-0.0.15 which is required by this ulogd2 release.

2008-Jul-23

iptables 1.4.2-rc1 released

The Netfilter Core Team has released iptables-1.4.2-rc1.

2008-Jul-09

libnetfilter_conntrack release

The netfilter core team has released libnetfilter_conntrack-0.0.96 that fixes minor compilation issues.

2008-Jun-27

libraries releases

The Netfilter Core Team has released:

This release set includes several bugfixes. Please, upgrade!

2008-Jun-17

iptables 1.4.1.1 released

The Netfilter Core Team has released iptables-1.4.1.1, a pure bugfix release for regressions reported against the 1.4.1 release.

2008-Jun-10

iptables 1.4.1 released

The Netfilter Core Team has released iptables-1.4.1.

2008-Jun-06

iptables 1.4.1-rc3 released

The Netfilter Core Team has released iptables-1.4.1-rc3.

2008-May-31

libnfnetlink 0.0.38, libnetfilter_conntrack 0.0.94 and conntrack-tools 0.9.7 released

The Netfilter Core Team has released libnfnetlink-0.0.38, libnetfilter_conntrack-0.0.94 and conntrack-tools-0.9.7.

2008-May-26

iptables 1.4.1-rc2 released

The Netfilter Core Team has released iptables-1.4.1-rc2.

2008-May-19

iptables 1.4.1-rc1 released

The Netfilter Core Team has released iptables-1.4.1-rc1.

2008-May-16

Moving to git

We are moving from subversion to git. You can access Netfilter's git web from http://git.netfilter.org/. Please, update your bookmarks.

2008-May-15

Netfilter workshop 2008 announced

The Netfilter workshop 2008 has been announced and the official webpage is online. This years workshop will be held in Paris, France, from September, 29th to October, 3rd. More details are available at the workshop page.

2008-Mar-09

libnfnetlink release

The netfilter core team has released libnfnetlink-0.0.33. This release includes minor updates. Upgrade is recommended.

2008-Mar-08

conntrack-tools 0.9.6 release

The netfilter core team has released conntrack-tools-0.9.6, another development release of the conntrack-tools. This upgrade includes tons of improvements, new features and bugfixes:

  • IPv6 support and new manpage for conntrackd
  • XML and timestamp support for conntrack
  • Secmark support
  • Improved performance
  • Support for VLAN interfaces
  • Support for related connections and NAT sequence adjustments (helpers)
  • Improved statistics support
  • Tons of cleanups and improvements from Max Kellermann

2008-Mar-07

libnetfilter_conntrack

The netfilter core team has released libnetfilter_conntrack-0.0.89 which includes new features and minor fixes. This release explicitly mark as deprecated the old API as it will removed in the future. Upgrade is recommended.

2007-Dec-22

iptables release

The netfilter core team has released iptables-1.4.0. This is the first final release of the new iptables branch 1.4. This release contains lots of bugfixes and improvements for the previous release candidate which strongly improves IPv6 support. Please, upgrade!

2007-Nov-28

Michael Rash's book on Linux Firewalls and IDS/IPS

Linux Firewalls is subtitled "Attack Detection and Response with iptables, psad, and fwsnort", and focuses heavily on what is possible from an intrusion detection and prevention standpoint within the context of iptables. There are many books that discuss firewall concepts and still other books that discuss intrusion detection, but none that really focus on the combination of the two technologies. Significant coverage in Linux Firewalls is devoted to seeing how attacks appear within iptables logs (with automated analysis performed by psad), and how the string match extension is used by fwsnort to detect application layer attacks. The book has two chapters on port knocking and Single Packet Authorization, and wraps up with a set of visualizations with Gnuplot and AfterGlow of iptables log data from the Honeynet project. The book is available for a substantial discount at:

http://www.nostarch.com/firewalls_mr.htm

An online site for the book is maintained here at:

http://www.cipherdyne.org/LinuxFirewalls

2007-Nov-16

libnetfilter_conntrack release

The netfilter core team has released libnetfilter_conntrack-0.0.82 that includes TCP flags support and one bugfix for big-endian platforms. Upgrade is recommended.

2007-Oct-15

iptables release

The netfilter core team has released iptables-1.4.0rc1. This is the first release candidate of the new iptables branch 1.4. This release candidate adds support for the generic xtables infrastructure that strongly improves IPv6 support. Also several accumulated bugfixed are included. Test it!

2007-Aug-08

Netfilter-related Linux kernel security updates

Nowadays, Linux Kernel related security issues are handled through the -stable series. Since the Netfilter project has part of his software in the Linux kernel, please do not expect to find updated kernel-related security announces in our security section. That section will contain only userspace-related problems (i.e. those regarding libraries and tools).

2007-Aug-07

libnetfilter_queue release

The netfilter core team has released libnetfilter_queue-0.0.15 that contains the index2interface API introduced by Eric Leblond. Upgrade is recommended.

2007-Jul-31

libnfnetlink release

The netfilter core team has released libnfnetlink-0.0.30. This release includes several bugfixes and the index2interface API. Upgrade is strongly recommended.

2007-Jul-29

conntrack-tools 0.9.5 release

The netfilter core team has released conntrack-tools-0.9.5. This release includes important improvements. Upgrade is strongly recommended.

2007-Jun-28

libnetfilter_conntrack release

The netfilter core team has released libnetfilter_conntrack-0.0.81 that includes minor changes and bugfixes. Upgrade is recommended.

2007-Jul-02

conntrack-tools 0.9.4 release

The netfilter core team has released conntrack-tools-0.9.4. This release includes several bugfixes and improvements. Upgrade is recommended.

2007-Jun-27

libnetfilter_conntrack release

The netfilter core team has released libnetfilter_conntrack-0.0.80 that includes accumulated bugfixes. Upgrade is recommended.

2007-Jun-25

iptables release

The netfilter core team has released iptables-1.3.8 that contains lots of accumulated bugfixes, manpage updates, and support for IPv6-MH, TCPMSS and port randomization for NAT. Upgrade is recommended.

2007-May-23

conntrack-tools release

The netfilter core team has released conntrack-tools-0.9.3 that contains the userspace daemon so-called conntrackd and a command line interface known as conntrack. Both tools let system administrators interact with the Netfilter Connection Tracking System from userspace, covering specific aspects of highly available firewall settings. Upgrade is recommended.

2007-May-22

libnetfilter_conntrack release

The netfilter core team has released libnetfilter_conntrack-0.0.75 that includes the new expectation API, some examples files under the utils/ directory and several bugfixes. Upgrade is recommended.

2007-May-07

Netfilter Workshop in Karlsruhe, Germany

Following the lastest successful workshop in Sevilla, Andalusia, Spain in september 2005. We are happy to announce the next edition in the workshop series. This year the event will be hosted in Karlsruhe, Germany from September 11th to 14th, 2007. For more information, please visit the official website of the workshop.

2007-Apr-16

New PGP key

The Netfilter Core Team has generated a new PGP key since the old one expired. We use this key to sign all software released by the project. For further information visit the PGP section in this homepage.

2007-Feb-21

New netfilter core team member: Pablo Neira Ayuso

The Netfilter Core Team is proud to announce the addition of Pablo Neira Ayuso as a new member.

He has repeatedly demonstrated high insight and coding standards, and has already been responsible for several parts of the codebase, especially ctnetlink, conntrack and conntrackd.

By joining the Core Team, Pablo will definitely help advance the development of the Netfilter project to a higher level.

2007-Jan-10

Library releases

The netfilter core team has released updates for several libraries: libnfnetlink-0.0.25 that introduces the new API, documentation, and fixes error handling; libnetfilter_conntrack-0.0.50 that also introduces the new API and documentation; and libnetfilter_queue-0.0.13 that contains one accumulated change.

2006-Dec-04

New iptables 1.3.7 release

The netfilter core team has released iptables-1.3.7. The 1.3.7 version is a maintainance release that contains accumulated bugfixes against iptables-1.3.6. This release fixes compilation issues with the recently released kernel 2.6.19.

2006-Sep-28

New iptables 1.3.6 release

The netfilter core team has released iptables-1.3.6. The 1.3.6 version is a maintainance release that contains accumulated bugfixes against iptables-1.3.5.

2006-Jan-31

New iptables 1.3.5 release

The netfilter core team has released iptables-1.3.5. The 1.3.5 version is a maintainance release that contains accumulated bugfixes against iptables-1.3.4. It also fixes some compilation issues with certain old kernel header versions.

2006-Jan-25

New ulogd-1.24 release

The netfilter core team has released ulogd-1.24,

The releases is a strict maintenance release, since all new development happens in the ulogd-2.x branch.

Various fixes have been included since version 1.23, most imporantly errnoeus printing of PROTO=0 when an IP packet in reality has a different layer four protocol, and a postgresql plugin memory hole.

2006-Jan-09

New ulogd-2.00beta1 release

The netfilter core team has released ulogd-2.00beta1,

The releases is the first public beta of the next generation userspace logging daemon. It features packet-based logging with the iptables ULOG and NFLOG targets, as well as flow based logging (and accounting) via ip_conntrack_netlink and libnetfilter_conntrack.

Stable production systems should stay with ulogd-1.x until the 2.00beta series is over.

2006-Jan-07

New libnfnetlink, libnetfilter_conntrack and conntrack releases

The netfilter core team has released libnfnetlink-0.0.14, libnetfilter_conntrack-0.0.30 and conntrack-1.00beta1.

The releases now fully support nf_conntrack_netlink (which is expected in kernel 2.6.16).

2005-Nov-11

New libnfnetlink, libnetfilter_log, libnetfilter_queue, libnetfilter_conntrack and conntrack releases

The netfilter core team has released libnfnetlink-0.0.12, libnetfilter_log-0.0.11, libnetfilter_queue-0.0.11, libnetfilter_conntrack-0.0.27 and conntrack-0.98.

The releases now introduce the possibility to compile the full set of libraries without having current 2.6.14 kernel headers installed.

2005-Nov-05

New libnfnetlink, libnetfilter_log, libnetfilter_queue, libnetfilter_conntrack and conntrack releases

The netfilter core team has released libnfnetlink-0.0.11, libnetfilter_log-0.0.10, libnetfilter_queue-0.0.10, libnetfilter_conntrack-0.0.20 and conntrack-0.90.

Those releases basically mark the release of a complete userspace API for the recently-introduced nfnetlink_log, nfnetlink_queue and nfnetlink_conntrack subsystems of the 2.6.14+ kernels.

2005-Nov-03

New iptables 1.3.4 release

The netfilter core team has released iptables-1.3.4. The 1.3.4 version is a maintainance release that contains accumulated bugfixes against iptables-1.3.3. It also fixes some compilation issues with iptables <= 1.3.3 and kernel >= 2.6.14.

2005-Oct-14

New netfilter core team member: Yasuyuki Kozakai

The netfilter project announces that following its invitation, Yasuyuki Kozakai has joined the netfilter core team. This is considered as an appreciation of Yasuyukis ongoing contributions, especially in the nf_conntrack and ip6_tables parts of the netfilter project.

Yasuyuki Kozakai is employed by Toshiba Co (Japan), and working for the USAGI project.

2005-Sep-28

New planet.netfilter.org website goes online

The netfilter project has started the planet.netfilter.org website. It aggregates the RSS feeds of all (known) weblogs/diaries/journals of netfilter developers.

In addition to that, there is now a system-wide blosxom installation on people.netfilter.org. This means that netfilter developers who have an account on people.netfilter.org can very easily set up their own blog. Instructions have been added to ~/README.

2005-Sep-24

New libnfnetlink, libnfnetlink_conntrack and conntrack release

The netfilter project has released libnfnetlink-0.0.10, libnfnetlink_conntrack-0.0.10 and conntrack-0.81.

Each of those three releases is the first official release of the respective project. They're the counterparts to the first pieces of the "next generation" netfilter subsystem that will be present in the 2.6.14 linux kernel release.

libnfnetlink is the low-level userspace library for nfnetlink based communication between the kernel-side netfilter and the userspace world.

libnfnetlink_conntrack is the librarry for userspace access to the in-kernel connection tracking table

conntrack is a commandline program for listing, querying, deleting, updating entries in the connection tracking table. It also supports real-time tracing of connection tracking state changes (conntrack events).

2005-Jul-29

New iptables 1.3.3 release

The netfilter core team has released iptables-1.3.3. The 1.3.3 version is a maintainance release that contains accumulated bugfixes against iptables-1.3.2. It also adds support for the upcoming (kernel 2.6.14) NFQUEUE target.

2005-Jul-10

New iptables 1.3.2 release

The netfilter core team has released iptables-1.3.2. The 1.3.2 version is a maintainance release that contains accumulated bugfixes against iptables-1.3.1. No new matches/targets have been added.

2005-Mar-07

New iptables 1.3.1 release

The netfilter core team has released iptables-1.3.1. The 1.3.1 version contains some minor bugfixes against iptables-1.3.0.

2005-Feb-12

New iptables 1.3.0 release

The netfilter core team has released iptables-1.3.0. The final 1.3.0 version contains some minor bugfixes and is otherwise identical to the 1.3.0rc1 release candidate.

1.3.x is a major update to 1.2.11. Apart from fixing numberous bugs, it contains the much-hyped libiptc rewrite.

2005-Feb-01

New iptables 1.3.0rc1 release

The netfilter core team has released iptables-1.3.0rc1. This is a major update to 1.2.11. Apart from fixing numberous bugs, it contains the much-hyped libiptc rewrite.

2005-Jan-30

No more patch-o-matic-ng releases

The netfilter project ceased to issue 'official' patch-o-matic-ng releases.

Please use the most current daily snapshot available from ftp.netfilter.org.

2004-Sep-25

Proceedings of netfilter developer workshop 2004

The official proceedings of the netfilter developer workshop 2004 have been released. This is a recommended reading for anybody interested in current development and future plans of the netfilter project.

2004-Jun-21

Updated patch-o-matic-ng release

The netfilter core team has released patch-o-matic-ng-20040621. This is the second 'official' release of our collection of features available for kernels >= 2.4.19, and >= 2.6.0.

2004-Jun-21

New iptables 1.2.11 release

The netfilter core team has released iptables-1.2.11. This is a minor update to 1.2.10, just fixing a makefile issue on systems where /bin/sh is not bash.

2004-Jun-15

New iptables 1.2.10 release

The netfilter core team has released iptables-1.2.10. This is a maintainance release that contains lots of bugfixes that have accumulated since iptables-1.2.9.

2004-Mar-02

First patch-o-matic-ng release

The netfilter core team has released patch-o-matic-ng-20040302. It is the first release of our collection of features available for kernels >= 2.4.19, and >= 2.6.0.

2004-Feb-17

Out-of-court settlement with Allnet GmbH on GPL'd iptables

The Netfilter Core Team has reached an amicable agreement with Allnet GmbH, a Germany-based vendor of networking equipment. Allnet was using netfilter/iptables software in their products without adhering to the obligations of the GPL.

For more information, see the full press release.

2004-Jan-29

Core Team Announces Emeritus Members

The Netfilter Core Team has long discussed the issue of Core Team members who are no longer active. Dismissing them from the Core Team would deny them the benefits of such a prestigious title, should any become apparent.

Hence the conclusion is that Marc Boucher, James Morris and Rusty Russell are now "emeritus" members of the Netfilter Core Team.

In this status, their involvement in the Core Team will be merely advisory. If they again become active and request reinstatement, they will return to full Core Team membership.

2003-Dec-24

New patch-o-matic release

The netfilter core team has released patch-o-matic-20031219. It contains the most up-to-date bugfixes and new features available for kernels >= 2.4.19, including 2.4.24. Please note that this release still does not yet support the just-released 2.6.0 kernel series. Expect a so-called 'patch-o-matic-ng' release for 2.6.x support in the next couple of weeks.

2003-Nov-02

New iptables 1.2.9 release

The netfilter core team has released iptables-1.2.9. This is a maintainance release that contains lots of bugfixes that have accumulated since iptables-1.2.8.

2003-Oct-17

Proceedings of the second netfilter developer workshop

It's been quite some time since the second netfilter developer workshop. Jozsef has now set up a small page containing some of the presentations and a summarry written by Harald.

2003-Oct-07

New iptables release candidate

The netfilter core team has released iptables-1.2.9rc1. This is the first release candidate for the upcoming 1.2.9 release. Please note that this is a release candidate not a final release. It is supposed to be stable, but might still contain minor glitches. If you are testing 1.2.9rc1 and run into bugs, please immediately report them to bugzilla.

2003-Oct-01

New patch-o-matic release

The netfilter core team has released patch-o-matic-20030912. It contains the most up-to-date bugfixes and new features available for kernels >= 2.4.18.

2003-Aug-23

netfilter.org up on new hardware

All netfilter.org services are moved to a new machine. If you still experience any problems, please contact Harald at hist gnumonks.org email address.

2003-Aug-22

netfilter.org system downtime

Due to an unexpected event, we were forced to take down the netfilter.org machine at the 19th of August. Because of the then ongoing netfilter workshop, we've been unable to start work on bringing the systems up again before Aug 21. As of now, www, mail (including lists), ftp, rsync and anoncvs are back up again. >developer cvs, bugzilla and cvsweb are still down. We are sorry for this unconvenience.

2003-Jul-30

Reprint of the netfilter T-Shirt

The long-awaited reprint of the netfilter T-Shirt has now arrived. They are plain white T-Shirts with the blue netfilter logo (as in the upper left corner of the homepage) printed on front. The shirts are available in sizes S,M,L,XL,XXL and are EUR 10 + shipping (EUR 5 intl. for one t-shirt) each. We accept orders at tshirt@netfilter.org.

2003-May-07

New coreteam member: Martin Josefsson

The netfilter core team has invited Martin Josefsson to join the coreteam. Martin is a dedicated member of the Netfilter development community with high insight and coding standards, who has already been responsible for several parts of the codebase.

2003-May-03

Netfilter Developer Workshop 2003

The netfilter core team proudly announces the second netfilter developer workshop, taking place from Aug 18 - Aug 20 2003 in Budapest, Hungary.

2003-Apr-13

New iptables-1.2.8 release

The netfilter core team has released iptables-1.2.8. It contains lots of minor bugfixes that have accumulated since the 1.2.7a release.

2003-Jan-16

netfilter/iptables bug tracking system

We finally started to use a full-fledged bug tracking system. Please have a look at the netfilter/iptables bugzilla.

2003-Jan-07

New patch-o-matic-20030107 release

The netfilter core team has released patch-o-matic-20030107. It contains the most up-to-date bugfixes and new features available for kernels >= 2.4.18.

2002-Aug-26

New iptables-1.2.7a release

The netfilter core team has released iptables-1.2.7a and patch-o-matic-20020825. Both contain important bugfixes for new bugs introduced by the iptables-1.2.7 and patch-o-matic-20020806 release.

2002-Aug-07

New iptables-1.2.7 release

The netfilter core team has released iptables-1.2.7 and patch-o-matic-20020806.

2002-Jul-11

Mailinglist problems

Due to yet unknown reasons, the netfilter and netfilter-devel lists have been deleted from lists.samba.org. While we are still investigating this problem, we have created new mailinglists at lists.netfilter.org. It is not clear whether there is a recent backup of the subscriber lists, so subscribing to the new lists is strongly recommended.

2002-Jun-22

Netfilter t-shirts

Netfilter t-shirts are now available. They are plain white t-shirts with the blue netfilter logo (as in the upper left corner of the homepage) printed on front. The shirts are available in sizes S,M,L,XL,XXL and are EUR 10 + shipping (EUR 5 intl. for one t-shirt) each. Please direct orders to tshirt@netfilter.org.

2002-May-08

We have issued a security announcement about a bug in the ICMP NAT code, resulting in a possible information leak


Copyright © 1999-2014 Harald Welte, Pablo Neira Ayuso . Pablo Neira Ayuso