Go wrapper around iptables utility
squeed Merge pull request #51 from squeed/iptables-nft
Add support for iptables in nftables mode.
Latest commit 47f22b0 Aug 3, 2018



Go bindings for iptables utility.

In-kernel netfilter does not have a good userspace API. The tables are manipulated via setsockopt that sets/replaces the entire table. Changes to existing table need to be resolved by userspace code which is difficult and error-prone. Netfilter developers heavily advocate using iptables utlity for programmatic manipulation.

go-iptables wraps invocation of iptables utility with functions to append and delete rules; create, clear and delete chains.