finds.dev← search

// the find

gamemann/xdp-firewall

★ 930 · C · MIT · updated May 2026

A firewall that utilizes the Linux kernel's XDP hook. The XDP hook allows for very fast network processing on Linux systems. This is great for dropping malicious traffic from a (D)DoS attack. IPv6 is supported with this firewall! I hope this helps network engineers/programmers interested in utilizing XDP!

A stateless XDP/eBPF firewall for Linux aimed at DDoS mitigation - CIDR range drops, dynamic rule-based filtering by IP/port/protocol/TTL, and both flow- and IP-based rate limiting, with live rule updates via pinned BPF maps. For network engineers running Linux edge boxes who want kernel-bypass packet dropping without pulling in iptables/nftables.

Runtime rule updates without restarting the program, via pinned BPF maps and companion xdpfw-add/xdpfw-del CLI tools - useful for wiring into an external blocklist feed. Supports IPv4 and IPv6, CIDR range drops, and both flow-based and per-IP rate limiting with configurable thresholds. Uses bpf_loop() to scale past the ~60-rule ceiling of unrolled loops on kernels 5.17+, and the README is upfront about the kernel version tradeoffs (5.3 minimum, 6.4 recommended for open-coded iterators) instead of glossing over them. CI actually compiles and runs the XDP/BPF program, not just the loader.

Explicitly stateless by design - no connection tracking or SYN cookie support, and the author has no plan to add it, so it won't help with spoofed SYN floods beyond blunt rate limiting. The author's own docs admit rule matching is a linear for-loop over a BPF array map, so throughput degrades as you add filter rules - it's not built to scale past a few hundred active rules. Filter-match logging via the ring buffer has no rate limiting, so turning on logging during the attack you're actually trying to observe adds CPU and disk load. Hardware offload mode is wired up but the author states no current NIC can actually offload the full program due to BPF complexity, so that feature is mostly aspirational.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →