4 ms·
> This experience is much better than the traditional iptables approach, where the 'load from file' and 'save to file' operations have the feel of a hack rather
by TwoNineFive 4y ago
> This experience is much better than the traditional iptables approach, where the 'load from file' and 'save to file' operations have the feel of a hack rather than a designed format and it can be easier to automate your rule setup with a script.
I found that statement to be weird given the existence of iptables-save and iptables-restore.
Anyway.
I manage a large fleet of OpenWRT devices with some crazy iptables stuff.
I have played with NFT multiple times over the last decade. It's never gone well. Like systemd and wayland it's being over-hyped by influenced teenagers that don't know what they are talking about and distro-paid bloggers.
NFT has a lot of problems and there's still a few things that it can't do, mostly because of missing modules.
I hope some day NFT becomes a good proper successor to iptables, but unfortunately the transition has been really slow, drawn out, and it's being pushed as a solid solution when it's just not ready.