

I was about to say the same – and also: nftables syntax is a lot cleaner compared to iptables, and the whole configuration can be loaded from a single file just like pf, without doing the dump/reload cycle that iptables required. Unless UFW does features like defining zones which a user might need (like firewalld), then it’s not a huge improvement on bare nftables usability-wise.



Not to mention, that this is an artist-enhanced version of composite pictures released by NASA that was included with MacOS X 10.7 as the default wallpaper … so not really a photograph either.