3 ms·
I was confused with this as well and the documentation is not always clear about it. Nftables and the netfilter project is the firewall implementation in Linux
by smashed 3y ago
I was confused with this as well and the documentation is not always clear about it.
Nftables and the netfilter project is the firewall implementation in Linux.
The legacy and beloved iptables format is fully replaced nowadays by nftables. You don't have to learn anything new because the iptables command line is just a compatibility layer on top of nftables with full compatibility. When you insert iptables rules, they get translated to nftables seamlessly. This has been the default on all major distros for years.
Converting to nftables has a few neat advantages such as much improved set/map and verdict tables support, unified IPv4, IPv6 and bridge rules, etc. But you don't have to. Everything old still works.
Flow tables is an optional feature of netfilter, I think originally meant to interface with hardware NAT accelerators in cheap routers, but it also has a pure software default implementation that can speed things up in some cases. That's what is being discussed in this article.
You use nftables to define and hook into flow tables. They work together, not against each other.