Files
buildroot/package/iptables/Config.in
Fiona Klute (WIWA) 2625440614 package/iptables: optionally default to nftables compat
For an nftables-based firewall setup it may be desirable to use
iptables-nft as the "iptables" binary, in particular to better
integrate legacy applications that do not support nftables directly
and call iptables. If the BR2_PACKAGE_IPTABLES_NFTABLES_DEFAULT option
introduced by this patch is enabled, iptables, iptables-restore, and
iptables-save are symlinked to the -nft version of iptables. The
-legacy options can still be called directly if desired.

Signed-off-by: Fiona Klute (WIWA) <fiona.klute@gmx.de>
Signed-off-by: Julien Olivain <ju.o@free.fr>
2025-02-28 21:10:41 +01:00

44 lines
1.1 KiB
Plaintext

config BR2_PACKAGE_IPTABLES
bool "iptables"
help
Linux kernel firewall, NAT, and packet mangling tools.
http://www.netfilter.org/projects/iptables/index.html
if BR2_PACKAGE_IPTABLES
config BR2_PACKAGE_IPTABLES_BPF_NFSYNPROXY
bool "bpfc and nfsynproxy"
select BR2_PACKAGE_LIBPCAP
help
Build bpf compiler and nfsynproxy configuration tool.
config BR2_PACKAGE_IPTABLES_NFTABLES
bool "nftables compat"
# uses dlfcn
depends on !BR2_STATIC_LIBS
depends on BR2_USE_WCHAR
depends on BR2_TOOLCHAIN_HEADERS_AT_LEAST_3_12
select BR2_PACKAGE_LIBMNL
select BR2_PACKAGE_LIBNFTNL
help
Build nftables compat utilities.
if BR2_PACKAGE_IPTABLES_NFTABLES
config BR2_PACKAGE_IPTABLES_NFTABLES_DEFAULT
bool "use nftables compat by default"
help
Make the nftables compat variant of iptables, iptables-save,
and iptables-restore the default. This only adjusts symlinks
in /usr/sbin, the legacy variants can still be called
directly.
endif
comment "nftables compat needs a toolchain w/ wchar, dynamic library, headers >= 3.12"
depends on !BR2_TOOLCHAIN_HEADERS_AT_LEAST_3_12 || \
!BR2_USE_WCHAR || BR2_STATIC_LIBS
endif