@loweel @feld @qdemouliere
The main one: rather than series of rather ugly command-line `iptables -A` calls, `nftables` is a quite elegant language.