Renaming the subject to make it to start a new discussion on something related. Cc'ing Patrick too, perhaps he can pull some better idea out of his hat. On Tue, Aug 26, 2014 at 11:57:16AM +0200, Arturo Borrero Gonzalez wrote: > This code examples uses the new NFT_MSG_DELTABLE functionality to replace > an entire ruleset in a single transaction/batch. Thanks for the example but we already have quite a lot of them, and this is yet another almost copy and paste that would need to be maintained. Please, implement this in nft. I think we can probably have an -x option, eg. nft -f -x ruleset-file The '-x' indicates that you want to flush any previous existing configuration before loading this 'ruleset-file'. -xx could also be used to remove any configuration regarding the existing families in the ruleset-file, ie. if the ruleset-file only contains a configuration for 'ip', all remaining families are left untouched. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html