Re: [DNG] my experience upgrading to NFT

2020-08-17 Thread tom
On Mon, 3 Aug 2020 09:10:46 -0700 Ian Zimmerman wrote: > On 2020-08-02 22:35, Hendrik Boom wrote: > > > Does iptables still work on beowulf? > > As long as you use update-alternatives to choose > /usr/sbin/iptables-legacy. Please see the other subthreads - I am new > to this topic myself, in

Re: [DNG] my experience upgrading to NFT

2020-08-03 Thread Marjorie Roome via Dng
On Mon, 2020-08-03 at 13:26 +0200, Tito via Dng wrote: > did you try update-alternatives to set iptables to iptables-legacy > behaviour. Arno-iptables-firewall and xtables-addons-dkms from > testing work for me that way. > The first machine I updated to Beowulf from Ascii was a clean install (but

Re: [DNG] my experience upgrading to NFT

2020-08-03 Thread Ian Zimmerman
On 2020-08-02 22:35, Hendrik Boom wrote: > Does iptables still work on beowulf? As long as you use update-alternatives to choose /usr/sbin/iptables-legacy. Please see the other subthreads - I am new to this topic myself, in fact I have not realized until today that I was running nftables for mont

Re: [DNG] my experience upgrading to NFT

2020-08-03 Thread Tito via Dng
On 8/3/20 10:53 AM, Marjorie Roome via Dng wrote: > On Fri, 2020-07-31 at 18:44 -0700, Thomas Groman via Dng wrote: >> I upgraded one of my larger and more complex servers from ASCII to >> Beowulf. Switching to NFT was very easy after the upgrade. Just >> create the rules, (have flush have the be

Re: [DNG] my experience upgrading to NFT

2020-08-03 Thread Marjorie Roome via Dng
On Fri, 2020-07-31 at 18:44 -0700, Thomas Groman via Dng wrote: > I upgraded one of my larger and more complex servers from ASCII to > Beowulf. Switching to NFT was very easy after the upgrade. Just > create the rules, (have flush have the beginning), remove the > iptables if-pre-up hook if you mad

Re: [DNG] my experience upgrading to NFT

2020-08-03 Thread Joel Roth via Dng
Thomas Groman via Dng wrote: > I upgraded one of my larger and more complex servers from ASCII to > Beowulf. Switching to NFT was very easy after the upgrade. Just create > the rules, (have flush have the beginning), remove the iptables > if-pre-up hook if you made one, copy the example init script

Re: [DNG] my experience upgrading to NFT

2020-08-02 Thread Simon Walter
On 2020-08-03 07:36, Ian Zimmerman wrote: > On 2020-08-02 17:00, Hendrik Boom wrote: >> What is NFT? > > nftables, the slowly arriving successor to iptables. > https://wiki.debian.org/nftables I've been using Shorewall for years. I only just now learned that: https://sourceforge.net/p/shorewall

Re: [DNG] my experience upgrading to NFT

2020-08-02 Thread Hendrik Boom
On Sun, Aug 02, 2020 at 03:36:46PM -0700, Ian Zimmerman wrote: > On 2020-08-02 17:00, Hendrik Boom wrote: > > > > I upgraded one of my larger and more complex servers from ASCII to > > > Beowulf. Switching to NFT was very easy after the upgrade. Just > > > create > > > > What is NFT? > > nftable

Re: [DNG] my experience upgrading to NFT

2020-08-02 Thread Ian Zimmerman
On 2020-08-02 17:00, Hendrik Boom wrote: > > I upgraded one of my larger and more complex servers from ASCII to > > Beowulf. Switching to NFT was very easy after the upgrade. Just > > create > > What is NFT? nftables, the slowly arriving successor to iptables. -- Ian __

Re: [DNG] my experience upgrading to NFT

2020-08-02 Thread Hendrik Boom
On Fri, Jul 31, 2020 at 06:44:16PM -0700, Thomas Groman via Dng wrote: > I upgraded one of my larger and more complex servers from ASCII to > Beowulf. Switching to NFT was very easy after the upgrade. Just create What is NFT? -- hendrik > the rules, (have flush have the beginning), remove the ip

[DNG] my experience upgrading to NFT

2020-08-02 Thread Thomas Groman via Dng
I upgraded one of my larger and more complex servers from ASCII to Beowulf. Switching to NFT was very easy after the upgrade. Just create the rules, (have flush have the beginning), remove the iptables if-pre-up hook if you made one, copy the example init script from /usr/share/doc/nftables/example