Issue #12 on hold

New backend: nftables

Richard Hering
created an issue

hi, please add support for nftables, here ist the Netlink API for the nftables subsystem: http://git.netfilter.org/libnftnl/tree/

Comments (9)

  1. Alex Xu

    the solution is to use the correct function of nft. firstly, just like iptables, separate chains are supported so that one can be assigned to a firewall generator process like sshguard. secondly, for cases like this, instead of adding individual rules which is very inefficient at evaluation time, a set should be used, ipset or nft set.

    edit: it seems I was misled by the (very?) out-of-date documentation. the point is that nft (now?) supports sets.

