Impacts of Replace Venerable Iptables and Embrace Nftables in a new futuristic Linux firewall framework

Praveen Likhar, Ravi Shankar Yadav · 2021

Firewall is a cardinal element in network security paradigm, where it is a measure for providing network access control. Iptables/netfilter is the most popular Linux firewall and over the time iptables has been extensively evolved and extended but as a result of this it became complex. Fundamental design limitations of iptables and its inherent problems are hindrance for its scalability and performance. This paper presents impeding factors in development of iptables and discusses about nftables, a new futuristic Linux firewall framework. It brings out nftables design approach for overcoming the limitations of iptables. This paper also expatiate comparison of iptables and nftables frameworks on different aspects and discusses results and analysis of our experimentations, to find out “Is it right time to embrace nftables over iptables?

Read the paper · More papers on PaperTik