Hacker News new | ask | show | jobs
by 5e92cb50239222b 1723 days ago
> 4. Firewalls require two sets of independent entries for the same service.

Depends on the exact rule you're writing, but nftables can remove a lot of duplication. Many rules cover both IPv4 and IPv6. It's the default since Debian 11.