3 ms·
Most people don't need anything more complex than this for their firewall needs, so iptables is overkill. Not only that, but iptables is just terrible to use a
by NetStrikeForce 9y ago
Most people don't need anything more complex than this for their firewall needs, so iptables is overkill.
Not only that, but iptables is just terrible to use and it just makes you want to kill yourself.
I've deployed a pretty standard policy now in DO with a couple of clicks, works as expected.
(And before anyone jumps, you should be using a host firewall too; defence in depth)
- egeozcan 9y ago> Not only that, but iptables is just terrible to use and it just makes you want to kill yourself. I can't agree more. Luckily though, if you have some setup scripts that you reuse, you don't have to think about iptables... Until the moment that you need to make this harmless quick change that shouldn't cause any problems and you end up locking yourself out of the server somehow.
- tasn 9y agoiptables is terrible, but nftables is great and mostly available. I wrote a post about my nftables config a while back. Plug: https://stosb.com/blog/explaining-my-configs-nftables/ https://stosb.com/blog/explaining-my-configs-nftables/