finds.dev← search

// the find

gamemann/xdp-proxy

★ 341 · C · MIT · updated May 2026

A stateless, high-performance NAT-like proxy that attaches to the XDP hook in the Linux kernel using (e)BPF for fast packet processing. This proxy forwards packets based on configurable rules and performs source-port mapping, similar to IPTables and NFTables.

A stateless XDP/eBPF packet proxy that does L3/L4 forwarding with source-port mapping, attaching at the XDP hook to run ahead of the normal netfilter path. Aimed at people doing high-throughput or low-latency Linux packet forwarding who'd otherwise reach for iptables/nftables DNAT rules but want to stay in kernel-bypass-adjacent territory.

Attaching at DRV-mode XDP means forwarding decisions happen before SKB allocation, which is a real latency win over netfilter-based NAT, not just a marketing claim. Pinned BPF maps plus separate xdpfwd-add/xdpfwd-del CLI tools let you add or remove forward rules on a running instance without restarting the proxy or losing existing port mappings. Runtime config supports periodic reload from disk (update_time), so most rule changes don't require a rebuild, only the truly structural stuff (like raising MAX_FWD_RULES) needs recompilation. CI actually builds the project on every push, which is more than a lot of BPF projects bother with.

Kernel requirements are a trap: you need 5.3+ for general BPF loop support and realistically 6.4+ for bpf_loop()'s open-coded iterators, and if you're stuck below that you have to hand-edit config.h and live with a hardcoded ~21 concurrent source ports, which defeats a lot of the point of source-port mapping. The forward rule cap (256, MAX_FWD_RULES) is a compile-time constant, not something you can bump without a rebuild and redeploy. There's no test suite in the repo, CI only checks that it compiles, so correctness of the actual NAT/port-mapping logic is unverified beyond manual testing. It's a single-maintainer project and genuinely stateless, meaning no connection tracking, so calling it 'NAT-like' undersells how much less it does than a real NAT gateway — fine for straightforward TCP/UDP/ICMP forwarding, not a safe drop-in for anything relying on connection state.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →