NetFilter SDK WFP driver¶
NetFilter SDK is a framework for transparent filtering of the data packets transmitted via network. This is a high-performance proxy-less solution, compatible with antiviruses/firewalls/other network filters. It is suitable for developing content filters, basic application level firewalls, traffic analyzers/shapers, and other software that requires viewing and modifying TCP/UDP traffic on Windows.
The SDK consists of kernel-mode and user-mode parts. The WFP kernel driver works on top of the TCP/IP stack and filters TCP/UDP protocols. Additionally, it is possible to filter any IP-based protocols on packet layers. It has a simple user-mode API, which can be used from C/C++/.NET/Delphi code.
Key features¶
The solution allows filtering incoming/outgoing TCP connections and UDP datagrams in user mode application. It is possible to filter the specified subset of connections/datagrams, restricted by filtering rules. The outgoing TCP connections can be redirected to a different address.
By default, the filtering is transparent to other filters, because the driver allows viewing and changing TCP/UDP data without redirecting the traffic to proxy and modifying the addresses. It minimizes the probability of conflicts with antiviruses, firewalls and other filters.
The filtering driver operates at the transport level, on top of the TCP/IP stack. As a result, it automatically supports all kinds of TCP/IP capable network adapters: Ethernet, Dial-up/DSL/Cable modems, wireless adapters including Wi-Fi and Bluetooth, virtual adapters like loopback or VPN.
Both IPv6 and IPv4 are supported.
The process context (such as the process identifier) is available for all network activity.
The driver user-level interface (API) is easy to use, but powerful.
It is possible to control the speed of data transmission and count the traffic.
The driver works in the same way on 32-bit and 64-bit Windows operating systems. It is possible to use 32-bit API for working with 64-bit driver.
- Installation
- Building drivers
- Using API
- Configurations
- Flow control contexts
- Driver registry settings
- Bind redirection
- I found a bug in the driver
- Signing the drivers
- Frequently asked questions
- API reference
- Functions
- Structures