|
|
|
|
|
by ta20210405
1899 days ago
|
|
>nftables (like iptables before it) is rule based and not bucket based. What does this even mean? Do you have any documentation to explain? >So high numbers of rules will not affect pf’s performance like it does with nftables. This is wrong. From OpenBSD documentation: "More lines being evaluated for each packet will result in slower performance." [0]https://www.openbsd.org/faq/pf/perf.html It's not 2001 any more. Nftables and Linux have left the BSDs in the dust. |
|
I posted the architectural diagrams of both in another comment on this thread yesterday, I think you missed that.