ns-dpi
Block traffic by application and protocol using the netifyd DPI engine.
How it works:
dpi-configturns/etc/config/dpiinto the netifyd flow actions config,/etc/netifyd/netify-proc-flow-actions.json- netifyd sets a conntrack label on the flows matching a rule
- the
dpi_actionsnft chain, written bydpi-nftin/usr/share/nftables.d/table-pre/, rejects the flows labellednetify-blocked
netifyd runs all the time: traffic is filtered as soon as one rule is enabled.
Flows seen on the WAN interfaces are excluded from the DPI rules (global iface == 'wan' exemption, as
in the netifyd 10-nfqueue.conf).
Rules and application groups are managed by the ns.dpi API, see packages/ns-api/README.md.
After editing /etc/config/dpi by hand, apply the changes with:
uci commit dpi
/etc/init.d/dpi reload
Configuration
Global options, in the config section:
log_blocked:1logs the blocked connections in/var/log/messages, with theDPI block:prefix
Application group (appgroup section), a named set of members:
ns_name: name of the groupapp: list of application names, as reported by the engine (e.g.netify.netflix)app_category: list of application category tags (e.g.games)proto: list of protocol names, as reported by the engine (e.g.HTTP/Connect)proto_category: list of protocol category tags
Rule (rule section):
ns_name: name of the ruleenabled:0or1action:blockorallowpriority: evaluation order, starting at1; the first rule matching a flow winsappgroup: list of application groups to matchsource: list of addresses, networks or ranges to narrow the rule to; empty means every hostns_match_all:1matches every flow instead of naming application groupsns_managed:1for the rules created by the APIcriteria: raw netifyd expression, used by the rules not created by the API; the API can’t edit them
Example:
config main 'config'
option log_blocked '1'
config appgroup 'ns_1a2b3c4d'
option ns_name 'Streaming and games'
list app 'netify.netflix'
list app_category 'games'
config rule 'ns_3869dc35'
option ns_name 'Allow the office'
option ns_managed '1'
option enabled '1'
option action 'allow'
option priority '1'
option ns_match_all '1'
list source '192.168.1.10'
config rule 'ns_9d40be71'
option ns_name 'Block streaming and games'
option ns_managed '1'
option enabled '1'
option action 'block'
option priority '2'
list appgroup 'ns_1a2b3c4d'
list source '192.168.1.0/24'
Migration from the previous schema
On upgrade, and every time the DPI service starts, /usr/libexec/ns-dpi/dpi-migrate converts the
configuration written before application groups existed, e.g. after restoring an old backup:
- every rule with
device,application,protocolorcategorybecomes an unmanaged rule, with its behaviour kept incriteria. Rules with an action other thanblock, such as the QoS ones (bulk,best_effort,video,voice), and rules matching nothing are dropped. The per-ruleexemptionandlogoptions are removed - every
exemptionsection becomes anallowrule at the top of the list, named after the exemption description popular_filtersis removed
Dropped rules and removed options are logged in /var/log/messages. The enabled and firewall_exemption
global options, which no longer switch anything, are removed on upgrade as well.
Troubleshooting
Check the generated rules:
cat /etc/netifyd/netify-proc-flow-actions.json
nft list chain inet fw4 dpi_actions
List the blocked connections:
conntrack -L -o label -l netify-blocked
Signatures and catalogs
dpi-updatedownloads the extra signatures, available only with a valid subscription, every night; run it by hand to force an update. On unregistration the extra signatures are removed and the ones shipped with the image are restoreddpi-data-updatedownloads the application and protocol catalogs (labels, categories, icons) into/etc/netifyd, every night