Is it Right Time to Repudiate Venerable Iptables and Embrace Nftables
Praveen Likhar, Ravi Shankar Yadav · 2021 Third International Conference on Inventive Research in Computing Applications (ICIRCA) · 2021
In present scenario where the global Internet traffic is reaching zettabytes and increased to almost threefold in last 3–4 years. Majority of this traffic is IP video traffic and global Internet traffic will keep on increasing exponentially. The performance is a major concern for all Internet based services and the overall network infrastructure has to be designed to deliver better performance. Firewall plays a very crucial role in any network infrastructure not only in security aspect but also with respect to network performance. Iptables is the most popular linux packet filtering framework and nftables is the new futuristic linux packet filtering framework intended to replace this existing venerable iptables. In this paper we are comparing both Linux firewall frameworks on various parameters. The experimentation and results of their performance on CentOS 8 is presented with detailed analysis.