-
Epic
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
None
-
nftables: Name-based flowtable hooks (with wildcard support)
-
36% To Do, 12% In Progress, 52% Done
-
rhel-net-firewall
-
False
-
-
Unspecified
-
Unspecified
-
Unspecified
When creating a new flowtable or netdev-family base chain in nftables, the specified interfaces should not need to exist already. Also, if such interface is removed/renamed and recreated (or another interface renamed to the old name) things should continue to function as expected.
A second feature (tightly connected to the above so handled as one here) is support for wildcard interface specs. Like with iifname/oifname matches, one might want to have a common netdev-family base chain for all interfaces matching a given name prefix.