Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sat Oct 19, 2013 9:25 pm 
Offline
Senior Member

Joined: Mon Jan 02, 2012 12:45 pm
Posts: 365
I just read that NFTables - a replacement for iptables - is going to be merged into the Linux 3.13 kernel. (http://www.phoronix.com/scan.php?page=n ... px=MTQ5MDU)

Here's info on the NFTables project: http://netfilter.org/projects/nftables

Is anyone familiar with NFTables?


Top
   
PostPosted: Sun Oct 20, 2013 5:11 am 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
Never heard of it. Just had a quick read, it'd be nice to have a one tool fits all system but apart from that it doesn't excite me. iptables will be around for a long while, I won't worry about this until I have to.

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
PostPosted: Sun Oct 20, 2013 5:42 am 
Offline
Senior Member

Joined: Mon Aug 29, 2011 2:34 am
Posts: 77
I spent 10 minutes staring at it when a friend linked me to it a while back, and 10 more minutes staring at when you linked to it here. Beyond that, I've not used it in any way. It does look really neat, and is even more powerful than the current set of iptables/ip6tables/ebtables/arptables (which is pretty hard to do), but as with most things that give you more power to do what you want, it's even less intuitive for new users, which, when it eventually fully replaces the existing tools, will make things like ufw and csf even more prevalent and probably make things worse than they were before. I can read and follow the flow of a ufw ruleset for iptables, but I shudder when thinking of what the nftables version would look like.

-Doug


Top
   
PostPosted: Mon Oct 21, 2013 10:47 am 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
obs wrote:
Never heard of it. Just had a quick read, it'd be nice to have a one tool fits all system but apart from that it doesn't excite me. iptables will be around for a long while, I won't worry about this until I have to.


iptables will be replaced with nftables in 3.13, as I understand it, although I believe there'll be a compatibility layer.


Top
   
PostPosted: Mon Oct 21, 2013 10:57 am 
Offline
Senior Member

Joined: Mon Aug 29, 2011 2:34 am
Posts: 77
Guspaz wrote:
iptables will be replaced with nftables in 3.13, as I understand it, although I believe there'll be a compatibility layer.


They aren't ripping out iptables/ip6tables/ebtables/arptables immediately. They'll coexist for a while (but may be set in the Kconfig to be mutually exclusive), until xtables can use the compatibility layer, and the large majority of the other kinks have been worked out. This probably won't occur until 3.17 or later, at a minimum.

-Doug


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group