Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And iptables has been around since 2001, and can still be used.

Alternatively you can use nftables which has only been around for the past 12 years.

I realise that one change per quarter century is possibly a little fast paced for BSD but I can cope with it.



PF is also from 2001. But its roots go further back, I once used a very PF-like syntax on a Unix firewall from 1997. I forget which type of Unix it was, maybe Solaris.

Either way, I don't think there is any defense for the strange syntax of IPtables, the chains, the tables. And that's coming from a person who transitioned fully from BSD to Linux 15 years ago, and has designed commercial solutions using IPtables and ipset.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: