Linux
Universal installation. Works on any distribution: Ubuntu, Debian, Fedora, Alpine, Arch, and others.
Install
curl -fsSL https://raw.githubusercontent.com/DanielLavrushin/b4/main/install.sh | sh
Or with wget:
wget -qO- https://raw.githubusercontent.com/DanielLavrushin/b4/main/install.sh | sh
The installer detects the architecture automatically, places the binary in /usr/local/bin, and creates the configuration in /etc/b4.
For a non-interactive install (default settings, no prompts):
curl -fsSL https://raw.githubusercontent.com/DanielLavrushin/b4/main/install.sh | sh -s -- --quiet
Without a terminal on standard input, for example under cron or over ssh without -t, the installer behaves as if --quiet had been given. --remove in that situation stops with an error unless --quiet is passed explicitly, since its prompts about deleting the configuration cannot be shown.
Service control
systemd (Ubuntu, Debian, Fedora, and most distributions)
systemctl start b4
systemctl stop b4
systemctl restart b4
systemctl status b4
systemctl enable b4 # autostart on boot
View logs:
journalctl -u b4 -f
OpenRC (Alpine)
rc-service b4 start
rc-service b4 stop
rc-service b4 restart
rc-update add b4 default # autostart on boot
SysV init (systems without systemd or OpenRC)
/etc/init.d/b4 start
/etc/init.d/b4 stop
/etc/init.d/b4 restart
/etc/init.d/b4 status
stop waits up to twenty seconds for the process to exit before killing it, and status exits with code 3 when b4 is not running.
Paths
| What | Where |
|---|---|
| Binary | /usr/local/bin/b4 |
| Configuration | /etc/b4/b4.json |
| Service (systemd) | /etc/systemd/system/b4.service |
| Service (OpenRC/SysV) | /etc/init.d/b4 |
Kernel modules
b4 uses NFQUEUE to intercept packets. The required kernel modules are usually loaded automatically when the service starts. If problems occur, they can be loaded manually:
modprobe nfnetlink_queue
modprobe xt_NFQUEUE
modprobe nf_conntrack
To verify:
lsmod | grep nfqueue
In LXC containers, kernel modules must be loaded on the host. The container config needs:
lxc.cgroup2.devices.allow: c 10:200 rwm
features: nesting=1,keyctl=1