Nftables: a new packet filtering engine
Posted Mar 24, 2009 17:25 UTC (Tue) by
JoeBuck (subscriber, #2330)
Parent article:
Nftables: a new packet filtering engine
If there were a translator that could take iptables rules and produce nftables rules, either the high-level form or the virtual machine form, then it seems that this change would be a no-brainer: iptables firewalls keep working and the kernel has a smaller, more flexible and powerful implementation. But without such a translator, users lose big-time.
So a translator should be a prerequisite for accepting nftables, because it allows iptables to go away.
(
Log in to post comments)