Why eBPF is the Future of Linux and Cloud Native Networking

For decades, IPtables has been the cornerstone of Linux networking, but that’s no longer the case. Over the last few years, extended Berkeley Packet Filter (eBPF) has emerged as a better option for Linux whether it’s running on-premises, or more likely than not, in the cloud. What eBPF provides is a low-level interface to enable […]

Published: Nov 18, 2020
Updated: Apr 22, 2021
2 minute read
Why eBPF is the Future of Linux and Cloud Native Networking
Enterprise Networking Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

For decades, IPtables has been the cornerstone of Linux networking, but that’s no longer the case. Over the last few years, extended Berkeley Packet Filter (eBPF) has emerged as a better option for Linux whether it’s running on-premises, or more likely than not, in the cloud.

What eBPF provides is a low-level interface to enable data packet transmission and control. On its own it has tremendous potential for networking. While there is lots of open source eBPF code now in the Linux kernel, on its own, it can be quite complex, which is where the open source Cilium project has been making inroads in the last few years.

I first wrote on Cilium in 2017, when the project first got started and the company behind it – Isovlanet – was still shrouded in stealth. Cilium and Isovalent are led by CEO and co-founder Dan Wendlandt, who helped to create the OpenStack Quantum networking project and was a pioneer in the Software Defined Networking (SDN) industry at VMware.

Last week, Isovalent emerged from stealth, along with $29 million in funding led by Andreessen Horowitz. Wendlandt and Andreessen Horowitz are hardly strangers; after he left VMware in 2016 he went to work as a partner at the venture capital firm, alongside fellow SDN pioneer and VMware alum Martin Casado.

Why an SDN Pioneer is Investing in eBPF

In a blog post announcing the investment in Isovalent, Casado said that with eBPF, it’s possible to write a program and embed it directly into the kernel. A common analogy: eBPF brings to the Linux kernel what JavaScript brought to the browser.

“With eBPF, you can see and control what is happening at the API level, showing the remote API calls being invoked and the data that they are being passed,” Casado wrote. “Cilium + eBPF is far more than API-aware visibility, it’s a fundamentally more powerful way to do networking in cloud environments, from traditional configurations on up, that allows for more robust program tracing, observability, and monitoring.”

That’s a fundamental shift from the legacy world of simply tracking data packets. The promise of eBPF is that networking isn’t just about moving packets, it’s about understanding what data is moving, how it can be controlled and how it can be secured.

Advertisement

In a cloud-native Kubernetes setting, eBPF and Cilium are already making significant inroads, and that’s why the company is raising money, so it can grow further with a commercially supported service. There are a lot of options for cloud networking and monitoring, but having kernel-level control is quite literally a new level of insight.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

Enterprise Networking Planet Logo

Enterprise Networking Planet aims to educate and assist IT administrators in building strong network infrastructures for their enterprise companies. Enterprise Networking Planet contributors write about relevant and useful topics on the cutting edge of enterprise networking based on years of personal experience in the field.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。