gamemann/xdp-firewall ? reverse-engineered prompt
Reverse engineered prompt
Build me a fast Linux firewall that runs in the kernel with XDP and eBPF, so it can drop bad traffic as early as possible, especially for DDoS protection. I want it to support blocking single source IPs, whole IP ranges with CIDR, and basic rule based filtering for TCP, UDP, ICMP, and IPv6. It should also keep real time packet counters so I can see what is being allowed and dropped, and have simple logging to the terminal or a file.
Please make it configurable from a file, with sensible defaults, and let me change things like the network interface, verbosity, stats, and whether maps are pinned. I also want a couple of small command line tools so I can add and remove blocked IPs without restarting the firewall. If you need to check the current docs for XDP or libbpf details, feel free to look them up online.
Are you gonna build this?
make sure you review the code using coderabbit