From mboxrd@z Thu Jan 1 00:00:00 1970 From: Stephen Satchell Subject: Re: Waiting until first release of NFTABLES Date: Mon, 24 Feb 2020 17:18:30 -0800 Message-ID: References: <875zfwssw1.fsf@goll.lan> <87r1yjqxki.fsf@goll.lan> Reply-To: list@satchell.net Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <87r1yjqxki.fsf@goll.lan> Content-Language: en-US Sender: netfilter-owner@vger.kernel.org List-ID: Content-Type: text/plain; charset="us-ascii"; format="flowed" To: netfilter@vger.kernel.org On 2/24/20 5:12 PM, Trent W. Buck wrote: > Can't you use "ip netns" (or systemd-nspawn, or docker, or libvirt-qemu) > to set up a test network with a test firewall, then send packets into / > out of that test environment? > > OK, it's a bit fiddly to set up, but I don't see why you need any > special nftables-specific thing when you can just do regular > namespace/container/vm techniques. HOWTO link?