[artix-general] iptables blocking dns queries

Qontinuum qontinuum at artixlinux.org
Fri Aug 20 18:08:23 CEST 2021


On Fri, Aug 20, 2021 at 11:48:40AM -0400, Ruben Safir wrote:
> I don't understand how they can move to nft if nft isn't close to being
> finished with no string matching?  Doesn't this leave firewalls across
> the entire internet exposed?

nft is already enough for a great majority of use cases for a long time
now.

I don't know if it support string matching but as already stated it has
raw expressions. Also, people don't expose private services to internet
and they use specialized software to do DPI.

-- 
qontinuum
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <https://lists.artixlinux.org/archives/artix-general/attachments/20210820/16d986a0/attachment.sig>


More information about the artix-general mailing list