On Sun, 2026-07-19 at 13:34 -0400, Phil Stracchino wrote: > > iptables, ipchains, nftables are all examples of utterly horrible > software design: An important tool whose syntax is not merely not > user-friendly, but actively user-hostile.
I don't really want this thread to veer too far off-topic but I don't think you are being at all fair to those tools. They are just tools and like any tool, you need to learn how to use it. Indeed, they are powerful tools and powerful tools take even more learning to understand how to use them. And because they are powerful and useful tools they are ripe for using as the building blocks in other, more intuitive, bigger picture tools. > It is the *operating > system*'s job to understand that internal firewall syntax, not the > user's. I can assure you that the presentation of the tools you describe is not at all what the operating system understands internally and what you are seeing is the human representation. > The user should be able to just *describe what they want to > happen* and then have that compiled into roles the OS understands, > and > that's what Shorewall does, and does it very well. And Shorewall is a perfect example of building a bigger picture tool on top of useful individual purpose-specific tools. Cheers, b. _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
