> Just to throw in another idea:
> How about using something like shorewall (shorewall.net) to handle the
> whole firewall generation code from a higher level. I'm using it for in
> really complex setups for years and i am very happy with it. (I know
> this won't solve the nftables problem right now).

No, I do not want to depend on such package.

_______________________________________________
pve-devel mailing list
[email protected]
https://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-devel

Reply via email to