3 ms·
> using the pf syntax and reloading the entire file will avoid reloading if there is a syntax error in a rule (iptables would run as a bash script and have unpr
by TwoNineFive 4y ago
> using the pf syntax and reloading the entire file will avoid reloading if there is a syntax error in a rule (iptables would run as a bash script and have unpredictable results)
False. iptables-save and iptables-restore does exactly that.
> - the syntax is fairly similar, but less ugly, similar to tcpdump
Also false and especially false and ignorant given the syntax complexity and non-friendliness has been a major complaint of the userbase since NFT's inception. But this isn't a suprise: nft syntax was purposefully designed to be better for computers at the expense of humans. It just happens to be that it's more difficult to write rules for humans, but easier for the interpreter and tools to work with them.