#1032315 provide separate packages for legacy and nft iptables

Package:
iptables
Source:
iptables
Description:
administration tools for packet filtering and NAT
Submitter:
Harald Dunkel
Date:
2026-02-06 20:43:02 UTC
Severity:
normal
#1032315#5
Date:
2023-03-03 15:25:06 UTC
From:
To:
Please move legacy iptables into separate packages to support
installing just the nft versions. We will never get rid of legacy
iptables/ip6tables if it is packaged together with nft for each
release.


Thank you very much in advance

Harri

#1032315#10
Date:
2026-01-31 14:41:44 UTC
From:
To:
Amen. +1. Signed.

This bug report is too wise and too important to lay around without any
maintainer reaction for three years. I want to be able to disable
iptables-legacy to make sure that there is nothing hanging arond.

That being said, I'd love to migrate away from iptables if nft one
reaches the maturity it desperately needs.

Greetings
Marc

#1032315#13
Date:
2026-01-31 14:41:44 UTC
From:
To:
Amen. +1. Signed.

This bug report is too wise and too important to lay around without any
maintainer reaction for three years. I want to be able to disable
iptables-legacy to make sure that there is nothing hanging arond.

That being said, I'd love to migrate away from iptables if nft one
reaches the maturity it desperately needs.

Greetings
Marc

#1032315#18
Date:
2026-02-06 20:40:40 UTC
From:
To:
The kernel team wants to remove support for the legacy kernel API once
Forky is released -- as I believe you are aware, Marc, because ISTR you
replied to the thread on -devel.  They are proposing that all users of
the API in user space should be removed in Forky.  On that basis, you
may expect a future upload of iptables with -legacy removed, once we've
done the due diligence to make sure the removal doesn't break stuff.

J.