1 |
On 02/28/2018 02:15 PM, Walter Dnes wrote: |
2 |
> Is there something besides iptables? |
3 |
|
4 |
nftables |
5 |
|
6 |
I think BPF may come into context here, but I've mostly ignored it, so |
7 |
I'm not sure. |
8 |
|
9 |
> It seems to be like systemd/perl/python, continuously expanding its scope. |
10 |
|
11 |
What do you mean? |
12 |
|
13 |
I've seen newer match extensions and targets over the years. But those |
14 |
are simply additional optional bits. I.e. you need to have the module |
15 |
loaded or compiled into your kernel. |
16 |
|
17 |
> I fondly remember IPCHAINS. |
18 |
|
19 |
I vaguely remember ipchains. I don't remember what was before it, |
20 |
ipfwadm(?). |
21 |
|
22 |
Maybe it was my ignorance at the time, but I wouldn't use the word |
23 |
"fondly" to describe my experience with ipchains. |
24 |
|
25 |
I am fond of iptables / ebtables / arptables. |
26 |
|
27 |
I've looked at nftables a few times in the last 18 months and have |
28 |
decided not to take that plunge yet. Usually it's because I feel like I |
29 |
don't have feature parity between iptables and nftables for the iptables |
30 |
features that I use. |
31 |
|
32 |
|
33 |
|
34 |
-- |
35 |
Grant. . . . |
36 |
unix || die |