5 ms·
I somehow like the iptables syntax better. Not just in the netfilter world but anywhere there are similar ideas. Why? Because it has a well defined structure f
by smallbigfish 9y ago
I somehow like the iptables syntax better. Not just in the netfilter world but anywhere there are similar ideas.
Why? Because it has a well defined structure for me.
For example '-j ACCEPT' signals my brain that I jump to a decision. I can also add after or before that a '-m comment', it will not change the jump decision I made already.
For the proposed bfp syntax it will take me 5 years to remember that the correct syntax is 'allow forward tcp' but not 'tcp forward allow' or any other combination.
(This is also part of the reason I didn't jump to nftables yet)