I was annoyed at first, but the transition is easy:
- iptables-translate can help convert rules
- nft avoids having to duplicate ipv4/ipv6 rules
- using the pf syntax and reloading the entire file will avoid reloading if there is a syntax error in a rule (iptables would run as a bash script and have unpredictable results)
- the syntax is fairly similar, but less ugly, similar to tcpdump