I've heard this about every linux firewall, can you give some good examples of what either iptables or nftables can't do that pf can?
But I find pf much easier to understand. I can write pf rules myself and understand, clearly, what my firewall is doing. I haven't found iptables near as approachable, and depend on firewall configuration tools to generate the rules and chains for me.
$ sudo iptables -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW -m recent --set --name SSH
$ sudo iptables -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 8 --rttl --name SSH -j DROP
Copied from http://kvz.io/blog/2007/07/28/block-brute-force-attacks-with... but I agree that pf ist just much more sane config wise.netfilter's iptables syntax well.. over the last, what, 10 years? we all got used to it. seems like nftables is going to required another 5 to become more or less known among people...
Tables?
Or my very favourite: last match wins, which shortens your ruleset considerably.
That said both of pf's versions look better than iptables. nftables looks like it does a better job of this like pf does, which is definitely a good thing.