Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.devel > #119702

Re: MBF: Removal of iptables-legacy

From Lucas Castro <lucas@gnuabordo.com.br>
Newsgroups linux.debian.devel
Subject Re: MBF: Removal of iptables-legacy
Date 2025-11-24 17:20 +0100
Message-ID <LUHsd-fqIO-1@gated-at.bofh.it> (permalink)
References <LUfmh-f7PC-7@gated-at.bofh.it> <LUk2C-faTf-27@gated-at.bofh.it> <LUkFj-fb6Y-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Em 23/11/2025 12:54, Vincent Danjean escreveu:
> Le 23/11/2025 à 16:12, Colin Watson a écrit :
>> [fixed typo in debian-kernel@ address]
>>
>> On Sun, Nov 23, 2025 at 10:57:39AM +0100, Bastian Blank wrote:
>>> The Debian Kernel team decided to deprecate and remove support for the
>>> legacy interfaces used by iptables, arptables and ebtables from the
>>> kernel.  The replacement nftables compatibility layer was introduced
>>> around 2016.  It is finally time to try and get rid of the legacy
>>> interfaces, which are now disabled by default in the kernel.
>>>
>>> Our plan is to drop usage in all packages and the binaries for forky.
>>> We will then go and remove the kernel support itself after the release
>>> of forky.  So in forky, using legacy iptables will still work, but
>>> Debian will not provide any support and consider it deprecated.
>
> I'm not sure to correctly understand.
> Is it only the kernel interface that will be removed (and the 
> 'iptables-legacy' package) ?
> Or would the binary 'iptables', ... from the 'nftables' package also 
> be removed ? (compat layer on top of nftables)
>
> I'm using the shorewall{,6} firewall for now. I've never found another 
> firewall packaged by Debian being able to handle multi-ISP (I would be 
> please to be wrong).
> If I recall correctly, shorewall relies on iptables (but works with 
> nftables compat layer) and upstream does not want to work on a switch 
> to a pure nftable implementation (too much work)[1]

I can't guess what problem you get when handling multi-ISP, but my guess 
that should be related against routing and not firewalling.


>
> Regards,
>   Vincent
>
> [1] https://gitlab.com/shorewall/code/-/issues/2
>

Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

MBF: Removal of iptables-legacy Bastian Blank <waldi@debian.org> - 2025-11-23 11:20 +0100
  Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-23 16:20 +0100
    Re: MBF: Removal of iptables-legacy Vincent Danjean <vdanjean.ml@free.fr> - 2025-11-23 17:00 +0100
      Re: MBF: Removal of iptables-legacy Lucas Castro <lucas@gnuabordo.com.br> - 2025-11-24 17:20 +0100
        Re: MBF: Removal of iptables-legacy Marc Haber <mh+debian-devel@zugschlus.de> - 2025-11-24 17:50 +0100
          Re: MBF: Removal of iptables-legacy Lucas Castro <lucas@gnuabordo.com.br> - 2025-11-24 18:00 +0100
    nft gripe (was: MBF: Removal of iptables-legacy) Marc Haber <mh+debian-devel@zugschlus.de> - 2025-11-23 17:30 +0100
    Re: MBF: Removal of iptables-legacy Bastian Blank <waldi@debian.org> - 2025-11-23 17:50 +0100
      Re: MBF: Removal of iptables-legacy Colin Watson <cjwatson@debian.org> - 2025-11-24 15:20 +0100
  Re: MBF: Removal of iptables-legacy Tianon Gravi <tianon@debian.org> - 2025-11-25 02:10 +0100
  Re: MBF: Removal of iptables-legacy Andrea Bolognani <eof@kiyuko.org> - 2026-01-07 02:50 +0100
    Re: MBF: Removal of iptables-legacy Jeremy Sowden <azazel@debian.org> - 2026-01-07 09:20 +0100

csiph-web