On 2024-08-13 20:32:02 [+0200], Florian Westphal wrote: > Or, just tag the x_tables traversers as incompatible with > CONFIG_PREEMPT_RT in Kconfig... After reading all this I am kind of leaning in for the Kconfig option because it is legacy code. Do you have any schedule for removal? There is nft and there is an iptables wrapper for it. It is around in Debian since Buster/ 2019 and only because it wasn't packaged in the previous releases. Sebastian