Recently, there have been discussions in the Linux networking community for the replacement of iptables with an eBPF-based approach. So far, the submitted work and ensuing discussions have been focused on the performance impact of the equation - which favor the eBPF approach. An approach to replace iptables with an eBPF backend without disrupting the user control has also been demonstrated. This talk builds on the above context and proceeds by presenting additional challenges that we feel need to be addressed so as to obtain a fully-compatible clone of iptables, i.e., to enable the eBPF-iptables tool to accept traditional iptables commands, which are emulated through the proper set of eBPF programs. Main challenges here are: