Processing nftable rules without loading them into the kernel

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I got a rather interesting task: I need to check if a given set of rules on the disk is the same as loaded into the kernel.

The main problem is that nft list is quite different from the original config (ordering, comments, etc), so I wonder if there is a way to make nft just to read rules, process them and output back in the same format as it is from nft ruleset list. Is there a way to force nft to just 'process' rules to stdout without loading them into the kernel?




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux