Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #227856

Re: Stretch => Buster: iptables

From Reco <recoverym4n@enotuniq.net>
Newsgroups linux.debian.user
Subject Re: Stretch => Buster: iptables
Date 2020-10-16 12:40 +0200
Message-ID <B0vjr-4f4-13@gated-at.bofh.it> (permalink)
References <B0v9L-4bV-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


	Hi.

On Fri, Oct 16, 2020 at 12:25:23PM +0200, Jesper Dybdal wrote:
> I have a lot of iptables rules.
> 
> Is it correctly understood that the upgrade to Buster will automatically install iptables-nft, and that iptablés-nft provides complete and compatible support
> for the functionality of the old iptables command, so I can expect my iptables scripts to just work?

Barring some kernel bugs - yes.
For instance, I've seen kernel panics because of simple:

iptables -A INPUT -m conntrack --ctstate INVALID -j DROP

It *should* be fixed by now, but I cannot call my own usage of netfilter
that advanced (filter, nat, *some* raw, that's it).


> (If so, that would be really nice, since I can then postpone the move to native nftables.)

To switch back to conventional netfilter you'll have to execute these:

update-alternatives --config iptables
update-alternatives --config ip6tables
update-alternatives --config arptables
update-alternatives --config ebtables

Last two are optional, and it all should be done after the migration to buster.

Reco

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 12:30 +0200
  Re: Stretch => Buster: iptables Reco <recoverym4n@enotuniq.net> - 2020-10-16 12:40 +0200
    Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 14:20 +0200
      Re: Stretch => Buster: iptables Pierre-Elliott Bécue <peb@debian.org> - 2020-10-16 16:30 +0200
  Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-11-06 10:50 +0100
    Re: Stretch => Buster: iptables Sven Hartge <sven@svenhartge.de> - 2020-11-06 11:50 +0100
      Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-11-06 12:10 +0100

csiph-web