Disclaimer: I'm not trying to start a religious war
As probably everyone knows, there is a generally "goodbye iptables (in fact netfilter), you served as well" fashion movement in the linux community. Redhat integrated nftables in their firewalld, Debian introduced nftables in latest buster release (on which Proxmox 6 is based) ... etc.
I was intrigued that Proxmox choose to "build" their firewall solution on bpfilter for their 6th release. I must confess that, except the part already included in tcpdump & friends, I am not very familiar with this "solution". And the general opinion (as far as I understood) is like "it should be the next successor - like ipchains > iptables > nftables > bpfilter, but it is not quite ready for full production, not necessarily because of stability, but the not-yet-implemented features".
Would you be so kind to give a little feedback about "why this decision" ? Thank you!
As probably everyone knows, there is a generally "goodbye iptables (in fact netfilter), you served as well" fashion movement in the linux community. Redhat integrated nftables in their firewalld, Debian introduced nftables in latest buster release (on which Proxmox 6 is based) ... etc.
I was intrigued that Proxmox choose to "build" their firewall solution on bpfilter for their 6th release. I must confess that, except the part already included in tcpdump & friends, I am not very familiar with this "solution". And the general opinion (as far as I understood) is like "it should be the next successor - like ipchains > iptables > nftables > bpfilter, but it is not quite ready for full production, not necessarily because of stability, but the not-yet-implemented features".
Would you be so kind to give a little feedback about "why this decision" ? Thank you!