netfilter project logo

Licensing information about netfilter/iptables

License terms of the netfilter/iptables software

netfilter/iptables is - like all of the Linux Kernel - Free Software (sometimes referred to as Open Source Software), distributed under the terms of the GNU GPLv2 only. Please, note that some source code files might differ, and in that case it is explicitely stated in the header of every file.

The GPL also contains some obligations. If you distribute netfilter/iptables code in binary form, you have to offer the source code, too.

The netfilter/iptables project has made available some more detailed information on this subject:

The TeX source code of those documents can be found here.

Contact the coreteam in case you have any further questions.

An article about netfilter licensing

Introduction

As netfilter/iptables is increasingly used by commercial vendors as part of their network security products, we'd like to give some explanations on how to comply with the license terms of this software.

The target audience for this document is somebody who re-distributes any software published by the netfilter/iptables project, independent of the medium of distribution (cd-rom, floppy disk, firmware image in flash/rom, internet download, ...).

Free Software ?!?

netfilter/iptables is, like the Linux operating system kernel itself, free software. Free refers to free as in freedom. It doesn't necessarily make a statement about the cost. Free does explicitly NOT mean free of any obligations.

Important

Free software is copyrighted material, very much like almost all software. You might have heard about freeware or public domain software. They are totally different concepts that do not apply to free software!

The GNU GPL Version 2

As many free software, netfilter/iptables is licensed under the terms of the GNU General Public License (GPL), Version 2. You can find the full text of this license at http://www.gnu.org/licenses/old-licenses/gpl-2.0.txt. There's also a comprehensive list of frequently asked questions available.

Important

The license enables you to distribute netfilter/iptables software ONLY IF you adhere to ALL conditions of this license. If you fail to do so, you are infringing our copyright in no different way of copying any other copyrighted material (e.g. proprietary software)!

In any doubt, feel free to contact the netfilter core team at BEFORE you ship any product containing our source code.

Obligations for distributing the original source code

According to Section 1 of the GNU GPLv2, you have the following obligations when distributing the original source code as published by the netfilter/iptables project:

  • Provide a copyright notice and disclaimer of warranty

  • Keep intact all notices that refer to the license

  • Give a copy of the GPL license along with the program

Obligations for distributing modified source code

According to Section 2 of the GNU GPLv2, you have the following obligations when distributing or publishing modified versions of the source code:

  • Every modified file has to carry a statement about the change, including the date of any change

  • You must make available any modified version available to be licensed as a whole at no charge to all parties under the terms of GNU GPLv2

Obligations for distributing object code / executable form

According to section 3 of the GNU GPLv2, when distributing or publishing either original or modified version of the program, you have to fulfill all the obligations of Section 1 and 2, plus one out of the two possible options:

  • Accompany it with the complete corresponding machin-readable source-code

  • Alternatively, accompany it with a written offer, valid for at least three years, to give any third party, for a charge no more than your cost of physically performing source distribution, a complete machine readable copy of the corresponding source code

Example case of an embedded firewall vendor

Let's assume you are a vendor that sells embedded firewalling devices, using any of the netfilter/iptables code. Let's assume you are shipping this device with pre-installed object code of the software (sometimes referred to as firmware), but also offer software updates via the internet.

Because of your specific needs, you had to modify parts of the original netfilter/iptables code to make it fit your requirements.

The GPL gives you two different ways of complying with the license. You can chose between both. However, the netfilter project prefers the option described first in this document:

Immediate source code offering

You have to accompany the device (as well as any version of a firmware update) with

A copy of the license text

A copy of the GNU GPLv2 License text along with your documentation, including a copyright notice (e.g. "(C) Copyright 2000-2004 netfilter project https://www.netfilter.org/") and the disclaimer of warranty (Section 11/12 of the GNU GPLv2).

If you ship printed documentation, please print the license, too. If you only ship electronic documentation (on CD-ROM or any other medium), please include an electronic version of the GNU GPL license text. If you ship GPL licensed code bundled with code subject to a different licese, you have to indicate which parts of the resulting product are covered by which license.

Full copy of the modified source code

Please remember that modifications from the original source need to be identified as modificiations.

Any scripts used to control compilation and installation of the object code

This specifically means you need to ship the makefiles used to control the build process and any tools needed for building the firmware image from the source code.

Written offer for source code shipping

In this case, you have to accompany the device (as well as any firmware update) with:

A copy of the license text

A copy of the GNU GPLv2 License text along with your documentation, including a copyright notice (e.g. "(C) Copyright 2000-2004 netfilter project https://www.netfilter.org/") and the disclaimer of warranty (Section 11/12 of the GNU GPLv2).

If you ship printed documentation, please print the license, too. If you only ship electronic documentation (on CD-ROM or any other medium), please include an electronic version of the GNU GPL license text. If you ship GPL licensed code bundled with code subject to a different license, you have to indicate which parts of the resulting product are covered by which license.

A written offer to provide the source code

It is important to note, that you have to offer the source code to any third party, not just to the customer who has bought your appliance. You are not allowed to charge more money than the cost of copying the media and shipping it to the requesting party. The source code has to oblige to the same criteria in the previous example (i.e. include makefiles, tools for building the firmware image, ...).

Notes on the development process

netfilter/iptables is a community based effort. This means that if it weren't for volunteers contributing source code to the project, it wouldn't exist and you wouldn't be able to build products based on it.

So as long as you want to continue selling netfilter/iptables products, it is in your own vital interest that the netfilter/iptables project flourishes. Contributions to the project are the most important part in the development of our project.

Important

All of this is optional. You are not required to support the netfilter/iptables project. We're just kindly asking you to do so.

Vendors are welcome to contribute their modifications and/or new features back to the project. This way we can consider to include them into one of our next releases, and thus increasing the value of our software.

There are lots of other ways how you can support and encourage further development of the netfilter/iptables software. Possible options include:

  • Monetary donations

  • Donations of hardware

  • Donations of rackspace, hosting, bandwidth, traffic

  • Directly funding the development of certain new features

  • Advertisement. Tell people that you are using our software

  • Bug fixing. Inform us if you have found and/or fixed any bugs in the software

If you are interested in supporting the netfilter/iptables project in any way, maybe even one not listed above, please don't hesitate to contact us at .

Frequently asked questions regarding GPL compliance and Netfilter

This section provides a list of frequently asked questions that may help you deal with GPL enforcement and Netfilter.

Where can I find information regarding compliance with netfilter’s license terms?

Netfilter provides useful information regarding the licensing terms for netfilter/iptables here. The netfilter community wants to help users to comply with the GPL.

Does netfilter enforce the GPL license?

Yes. The core team members of the netfilter project have officially endorsed and support "The Principles of Community-Oriented GPL Enforcement" in this public statement.

I have received a letter from Patrick McHardy demanding that I cease and desist from using "Netfilter" or "Linux Kernel Network Stack." Who is Patrick McHardy and what should I do?

On January 2022, the netfilter coreteam has announced a legally binding settlement with Patrick McHardy that governs any legal enforcement activities concerning all programs and program libraries published by the netfilter/iptables project on its website (https://www.netfilter.org) as well as the Linux kernel (https://www.kernel.org).

This settlement does not allow for unilateral copyright enforcement. It establishes that any decision-making around netfilter-related enforcement activities should be based on a majority vote of the active coreteam members at the time of the enforcement requests. This settlement covers past and new enforcement, as well as the enforcement of contractual penalties related to past declarations to cease-and-desist.

You can see the court order (in German) and/or the English translation of the court order for further details.


Copyright © 1999-2024 The Netfilter's webmasters . Contact webmaster