← Downloads

nftables 1.1.3

Package v1.1.3 x86_64 TAR.XZ April 22, 2025

The kernel packet filtering framework that replaced iptables, with one unified syntax, a single inet family covering IPv4 and IPv6, and native support for sets and maps.

Download TAR.XZ Project website ↗

Download Mirrors

Mirror Region Download
netfilter.org (Official) Primary Global Download
netfilter Git Global Download

nftables replaced iptables as the kernel packet filtering framework. On modern distributions, iptables is usually a translation layer sitting on top of it.

Why it replaced iptables

One tool instead of four. iptables, ip6tables, arptables, and ebtables each had their own syntax and their own tables. nftables handles all of it.

The inet family. One table covering both IPv4 and IPv6. With the old tooling you wrote every rule twice, and the classic failure was a host firewalled correctly on IPv4 and wide open on IPv6. Our IPv6 guide covers why that still catches people out.

Sets and maps natively, so matching a hundred addresses is one set lookup rather than a hundred rules evaluated in order.

The three rules that must come first

With policy drop, a ruleset that only allows port 22 will still break, because replies to your own outbound traffic are not new connections.

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;

    ct state established,related accept
    ct state invalid drop
    iifname "lo" accept
    meta l4proto { icmp, ipv6-icmp } accept

    tcp dport 22 ct state new limit rate 10/minute accept
  }

  chain forward { type filter hook forward priority 0; policy drop; }
  chain output  { type filter hook output  priority 0; policy accept; }
}

Every working ruleset starts with those first three lines. Our nftables rule builder generates them by default.

Test before applying

sudo nft -c -f /etc/nftables.conf     # check without applying
sudo nft -f /etc/nftables.conf
sudo nft list ruleset

A mistake in an input chain on a remote server locks you out immediately, with no equivalent of ufw asking whether you are sure. Always -c first.

Persisting

Rules added with nft add exist only in memory:

sudo nft list ruleset | sudo tee /etc/nftables.conf
sudo systemctl enable --now nftables

Migrating from iptables

iptables-translate -A INPUT -p tcp --dport 22 -j ACCEPT
iptables-restore-translate -f rules.v4 > ruleset.nft

The translation is mechanical and the output is usually worth rewriting by hand, since a direct translation carries the structure of the old tooling rather than using sets and the inet family properly.

Our nftables versus iptables comparison covers the transition.

Verify Your Download

Source releases on netfilter.org are published with GPG signatures.