3 ms·
It seems to me that the downside of this is that it (at least the default output) is even harder to read than iptables.
by Hello71 10y ago
It seems to me that the downside of this is that it (at least the default output) is even harder to read than iptables.
- Alupis 10y agoI think it does make a stab at making the rules a bit more "human friendly". iptables -A FORWARD -p tcp --dport 22 -j LOG iptables -A FORWARD -p tcp --dport 22 -j DROP vs: nft add rule filter forward tcp dport 22 log drop Less random-looking flags/switches, and more meaning to a human.
- loeg 10y agoThe hyphens gave a nice visual separation before.
- Rapzid 10y agoAgreed; the old way is much easier to skim IMHO (have not tried to skim large lists of the new style).
- bandrami 10y agoAgreed; I assume it would be more or less trivial to write an input filter so you can keep your old rules.
- Alupis 10y agonftables has a built-in compatibility layer for iptables and ipv6tables rules.
- aexaey 10y agoAlso: nft add rule nat ip saddr {10.0.0.0/8, 192.168.0.0/16} tcp dport {http, https} dnat 1.2.3.4 vs. iptables -t nat -A PREROUTING -m tcp -p tcp -s 10.0.0.0/8 --match multiport --dports 80,443 -j DNAT --to 1.2.3.4 iptables -t nat -A PREROUTING -m tcp -p tcp -s 192.168.0.0/16 --match multiport --dports 80,443 -j DNAT --to 1.2.3.4
- petre 10y agoI wonder if the nft rules are order sensitive, because iptables arguments shouldn't be.
- deleted 10y ago[deleted]
- petre 10y agoYes, the rule syntax is a bit like PF's, albeit still more complicated. I find iptables harder to use than PF/IPF or IPFW, not to mention Cisco rules. This is definitely an improvement over iptables from the usability standpoint.