Nftables: a new packet filtering engine
Nftables: a new packet filtering engine
Posted Mar 24, 2009 17:44 UTC (Tue) by yokem_55 (subscriber, #10498)In reply to: Nftables: a new packet filtering engine by JoeBuck
Parent article: Nftables: a new packet filtering engine
The main requirement for a translator though is that it cannot cause subtle changes in behavior between the original iptables implementation and the translated nftables implementation. It would seem to me that the less risky, and perhaps easier transition would be to mark iptables as deprecated, merge nftables in parallel with iptables, and in a couple of years pull the plug on iptables. By that time it should be clear if a translator can work reliably, and for most folks to implement their filters in nftables "native" code.
