Post #3456603
2026-06-28 21:48 UTC
@mathew@universeodon.com we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon.
I think it will take years before nftables works with everything just like it is with ipv6.
Replies (1)
-
@grono@mastodon.com.pl 2026-06-28 22:27
@koen@procolix.social FWIW in Docker there's an experimental nftables backend now: https://docs.docker.com/engine/network/firewall-nftables Give it a try!