netfilter.org states that "nftables is the project that aims to replace the existing {ip,ip6,arp,eb}tables framework." The nftables kernel code was merged into the mainline kernel in January 2014. So it's time to get started with the new Linux firewall framework on openSUSE.

One idea at the end of hackweek would be to have a radio button inside the YaST Firewall module to generate either iptables or nftables output rules.

DO NOT ENTER

Firewalling with nftables

Photo by gnu1742

Looking for hackers with the skills:

Nothing? Add some keywords!

This project is part of:

Hack Week 12

Activity

  • over 5 years ago: mrostecki liked this project.
  • over 5 years ago: mrostecki joined this project.
  • over 9 years ago: pluskalm liked this project.
  • over 9 years ago: abergmann liked this project.
  • over 9 years ago: mkubecek liked this project.
  • over 9 years ago: abergmann started this project.
  • over 9 years ago: abergmann originated this project.

  • Comments

    • mrostecki
      over 5 years ago by mrostecki | Reply

      Maybe we can consider enabling nftables as the default firewalld backend as a part of this project? We tried it once year ago, we failed because of some error from Docker. But it would be nice to try again.

    Similar Projects

    This project is one of its kind!