Website Security & Threat Management
How We Used eBPF to Build Programmable Packet Filtering in Magic Firewall

How We Used eBPF to Build Programmable Packet Filtering in Magic Firewall

12/6/2021 · Chris J Arges

What this post added

This post details the integration of eBPF with nftables within Cloudflare's Magic Firewall. It explains how eBPF programs can be loaded and executed within the kernel to provide advanced packet parsing and content matching capabilities beyond what nftables alone can offer. The post covers the technical challenges of bridging iptables' xt_bpf extension with nftables, the structure of netlink/netfilter messages required, and the process of compiling and loading eBPF programs using libraries like cilium's ebpf. This enables more sophisticated firewall rules for protocol validation and advanced field matching.

Read the original post ↗