Nftables
-
Testing routers with Linux network namespaces
A pattern I now use for testing every firewall and routing change before it touches the edge: cheap, repeatable, and on a laptop
-
nftables rule ordering surprised me
A two-hour outage caused by a harmless-looking rule insertion into the wrong chain position, and what I learned about nftables evaluation