LOFTVerified Migration of Linux Firewalls to SDN

Julius Michaelis 🌐 and Cornelius Diekmann 🌐

October 21, 2016

Abstract

We present LOFT — Linux firewall OpenFlow Translator, a system that transforms the main routing table and FORWARD chain of iptables of a Linux-based firewall into a set of static OpenFlow rules. Our implementation is verified against a model of a simplified Linux-based router and we can directly show how much of the original functionality is preserved.
BSD License

Topics

Theories of LOFT

Depends On