Hi, Is there a way to interact with the firewall rules from a C(++) program? What I'm really trying to do is have a program that only allows a certain set of CIDRs through the firewall through a particular port. However these CIDRs change from time to time and so my application is there to update the firewall rules to make sure that the firewall rules contain the latest and greatest information that says: "drop everything trying to connect to port P EXCEPT for stuff originating from these CIDRs". The information I've found so far seems to indicate I should look at libnftnl and nftables but I'm not sure this is right. Can you point me to the documentation for this? I've been looking online for information on how to do this but haven't found anything really. Thanks, Thomas
Attachment:
signature.asc
Description: OpenPGP digital signature