Conversation
With ipset-persistent, part of netfilter-persistent, the ipset is loaded earlier in the startup proces. The script in /etc/network/if-up.d can be removed.
|
how will a good use-case might look like to migrate the solution to nftables? |
|
Probably? Didn’t Debian move to nftables? At least the script doesn’t work for me on Debian 11… |
|
In any case, ipset and family has been deprecated on several distros including RHEL9. iptables has been deprecated in Debian 10: Alternatively since ipset version 7.12 you can use the ipset-translate utility which allows you to translate your existing ipset file to nftables. |
|
I've made an nftables version, if someone wants it - https://github.com/leshniak/nft-blacklist |
|
Great! Thanks. |
With ipset-persistent, part of netfilter-persistent, the ipset is loaded earlier in the startup proces.
The script in /etc/network/if-up.d can be removed.