4 ms·
Wow, amazed they have iptables (and ipsets) in the report but no mention of nftables in 2020. A 2017(!) test by RedHat[0] shows that nftables scales much bette
by 2bluesc 6y ago
Wow, amazed they have iptables (and ipsets) in the report but no mention of nftables in 2020.
A 2017(!) test by RedHat[0] shows that nftables scales much better with more complex rules then iptables. The original post shows the same, again surprised someone doing this much work on testing hadn't mentioned nftables.
Modern firewall utilities such as firewalld (for better or worse if it scratches your itch) have defaulted to nftables[1] when possible on platforms like Arch and probably Ubuntu at this point.
Ultimately iptables is discouraged by Debian[2] and the netfilter project[3].
[0] https://developers.redhat.com/blog/2017/04/11/benchmarking-nftables/ https://developers.redhat.com/blog/2017/04/11/benchmarking-n...
[1] https://firewalld.org/2018/07/nftables-backend https://firewalld.org/2018/07/nftables-backend
[2] https://wiki.debian.org/nftables#Should_I_build_a_firewall_using_a_nftables.3F https://wiki.debian.org/nftables#Should_I_build_a_firewall_u...
[3] https://wiki.nftables.org/wiki-nftables/index.php/Why_nftables%3F https://wiki.nftables.org/wiki-nftables/index.php/Why_nftabl...
- infogulch 6y agoWell, for better or worse, docker doesn't work with nftables (can't configure it automatically iirc) and given that half of the posts on this blog are container /kubernetes related I can see why they would focus on this one.
- mholmstrom 6y agoIt's no wonder nobody wants to touch it considering what an unhelpful piece of crap the nftables CLI configuration utility is $ nft list Error: syntax error, unexpected newline list ^ $ nft show Error: syntax error, unexpected newline, expecting string show ^ $ nft help Error: syntax error, unexpected newline, expecting string help ^
- TwoNineFive 6y agonftables has a lot of problems once you get past the extreme basics. It only got stateful support in like 2017/2018 and still can't do some important features for tunnels and ipsec. Nobody with real-world experience is going to using nftables yet, except as a proof of concept or for other esoteric reasons. The amount of paid blogverts pushing of nftables by Red Hat is pretty obvious. nftables might be good some day, but it's not there yet.
- hinkley 6y agoAny time someone says, "It's faster but it's missing important features," I just want someone to wake me up when the feature is there and the benchmarks are redone. Lots of code is faster when it's feature-deficient, and gets slower once it has covered the special cases.