Which is "better" for ease of control - iptables and nftables?

Do people out there have any strong opinions regarding

  • degree of ease of understanding firewall filterring rules?

  • degree of ability/scope to control?

  • degree of ease of fine tuning?

using one or the other?


BTW, not part of discussion, but I do NOT use UFW. No need for it!

2 Likes

well nftables is the future and IMO the better choice for ease of control too. It’s been the official successor since 2014 and every major distro defaults to it now, or uses iptables-nft as a compatibility shim. Even firewalld and UFW use it as their backend. So it’s arguably better time spent to focus on nftables.

3 Likes

as a sidenote:

I know that UFW stands for Uncomplicated Fire Wall.
I dived into it and found the tablesetup quite complicated :laughing:

(Please forgive me, I had a long and complicated day at work :squinting_face_with_tongue:)

4 Likes

Im sure pun intended! :melting_face:

2 Likes