[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

nft bewilderment



Buster, Supermicro desktop, nft noob

Can anyone recommend a book or website with a thorough explanation of
nft (the iptables replacement)?

I'm working on rewriting my aged packet filter shell script (big and
from the ipchains days) with nft and python. I've spent several hours on
the web, and I've found lots of info about nft, but nowhere have I come
across a plain and straightforward explanation -- lots of 'how nft is a
huge improvement over iptables', but very little about why or what
things mean or what's necessary to make things happen.

So far, the best I've been able to do is just change the commands in
examples and test them to see what happens.

Like, for one example: What's a 'base chain', what's not, why do both
exist, what's the functional difference, what do the various components
of the command line mean, etc.

-- 
Glenn English


Reply to: