[PATCH] wg-quick: linux: add support for nft and prefer it

Vasili Pupkin diggest at gmail.com
Tue Dec 10 23:27:56 CET 2019


On 11.12.2019 1:09, Jason A. Donenfeld wrote:
> On Tue, Dec 10, 2019 at 11:03 PM Vasili Pupkin <diggest at gmail.com> wrote:
>> As far as I know both of them are maintained in the same repository and
>> both use the same userspace library to interact with the kernel and down
>> there all the rules are translated into BPF code which in turn is
>> compiled into machine code by kernel BPF JIT compiler.
> "bpfilter" is a WIP, but that's not today how iptables or nftables
> work, at all. I'm not sure your statement about userspace is entirely
> correct either.
>
May be it is a road map plan and there will be no difference in 
performance when it will be implemented then. I just recall an 
announcement somewhere so it is just a speculation from my side, sorry


More information about the WireGuard mailing list