4 ms·
That's really weird. I haven't used nftables, but I'm planning to do so the next time I upgrade my router. https://stosb.com/blog/explaining-my-configs-nftables
by tsuraan 9y ago
That's really weird. I haven't used nftables, but I'm planning to do so the next time I upgrade my router. https://stosb.com/blog/explaining-my-configs-nftables/ https://stosb.com/blog/explaining-my-configs-nftables/ makes it look nearly as pretty as pf. Is there something under the hood that's awful?
- DrPhish 9y agoThat actually doesn't look too bad. I do wish they'd just adopted the PF syntax tho. It really is the gold standard for stateful firewall definition Was anyone involved in the discussions around the creation of nftables that can comment on whether this was considered?
- ahartmetz 9y agoLet's see: Getting started https://wiki.nftables.org/wiki-nftables/index.php/Main_Page#Basic_operation https://wiki.nftables.org/wiki-nftables/index.php/Main_Page#... None of these is anything like a tutorial or introduction. "Quick reference, nftables in 10 minutes" claims to be a ten-minute guide but it's actually just an information dump without any guidance. Some highlights: "matches are clues used to access to certain packet information and create filters according to them." My translation: "Matches are conditions for rules to apply. They match certain properties (hyperlink) of packets." "position is an internal number that is used to insert a rule before a certain handle." My translation: "position is an index into the list of rules. It can be used to insert rules at a given position in the list." I don't know if my translations are correct due to the absurdly bad originals. It is like the authors explain verbs without explaining the nouns they act on. For the nouns, there are mostly just tables of them without any explanation at all. In other places, the few most important nouns are explained. This alien logic is not only in the documentation, it is also in the syntax. Nobody I know thinks like that.
- alyandon 9y agoWow, that NAT syntax is just plain awful as well. :-/ For reference: https://wiki.nftables.org/wiki-nftables/index.php/Multiple_NATs_using_nftables_maps https://wiki.nftables.org/wiki-nftables/index.php/Multiple_N...