NETFILTER ARCHITECTURE. FUNCTIONAL TESTING IN ALT OS
Abstract
The article presents a practical study of the netfilter subsystem implementation in the Russian Alt OS. The relevance of the work is driven by the need to verify the correctness and completeness of fundamental network security mechanisms in domestic software. The research addresses the task of comprehensive functional testing of the netfilter architecture through its modern interface -- the nftables framework. A series of experiments was conducted on an isolated laboratory testbed simulating a corporate network segment. The testing covers key functionalities: packet filtering (ICMP, TCP, UDP), network address translation (NAT), packet header manipulation (mangle), and traffic management using rate limiting (limit) and stateless filtering mechanisms. Particular attention is paid to comparing the behavioral aspects of REJECT and DROP actions when blocking access. The results experimentally confirm the full correctness and predictability of all tested mechanisms. Load testing allowed for observing the impact of various filtering rules on the router's CPU load. A key practical result is the verification of the reference-standard implementation of netfilter in Alt OS, confirming its suitability for deploying mission-critical network infrastructure. The obtained data and testing methodology can be used for the certification and security audit of domestic Linux distributions. The study's conclusions indicate that the netfilter/nftables implementation in Alt OS is reference-standard and functionally identical to that in the standard Linux kernel. The presented results demonstrate the platform's readiness to serve as a foundation for building reliable and efficient corporate firewalls.
Online viewer
References
- Netfilter.org project. Netfilter hooks – nftables wiki [Электронный ресурс]. – URL: https://wiki.nftables.org/wiki-nftables/index.php/Netfilter_hooks (дата обращения: 14.12.2025).
- Документация ALT Linux Team [Электронный ресурс]. – URL: https://docs.altlinux.org/ru-RU/alt-server/11.1/html/alt-server/setup-inet-connection--chapter.html (дата обращения: 06.12.2025).
- Netfilter.org project [Электронный ресурс]. – URL: https://www.netfilter.org/ (дата обращения: 06.12.2025).
- Salah, K. Performance Modeling and Analysis of Network Firewalls / K. Salah, K. El-Badawi, A. El-Badawi // International Journal of Network Security & Its Applications. – 2012. – Vol. 4, № 2. – P. 69–82.
- Kadlecsik, J. Netfilter Performance Testing [Электронный ресурс] / J. Kadlecsik. – Netfilter.org, 2010. – 15 p. – URL: https://people.netfilter.org/kadlec/nftest.pdf (дата обращения: 11.12.2025).
- Уймин, А. Г. Сетевое и системное администрирование. Демонстрационный экзамен КОД 1.1 : учебно-методическое пособие для СПО / А. Г. Уймин. – 3-е изд. – Санкт-Петербург : Лань, 2022. – 480 с.
- Benchmarking Methodology for Firewall Performance : RFC 3511 [Электронный ресурс]. – IETF, 2002. – URL: https://www.rfc-editor.org/rfc/rfc3511.html (дата обращения: 11.12.2025).
License
Copyright (c) 2025 K. S. Tyukhtin (Author)