whatis nftables
nftables
Also known as: nft, iptables
The modern Linux packet filtering framework and nft command, replacing iptables with one unified syntax for IPv4, IPv6, and more.
What Is nftables in Linux?
nftables organizes rules into tables and chains that hook into the kernel's netfilter at points like input, forward, and output. One ruleset covers IPv4 and IPv6, and sets and maps make large rulesets fast.
Most distros now run nftables underneath, even when you use iptables commands through the iptables-nft compatibility layer. Rules persist in /etc/nftables.conf.
Example
sudo nft list ruleset Learn more about nftables
- nftables vs iptables nftables replaced iptables as the standard Linux packet filtering framework. This guide explains the differences, how to use both, and how to migrate from iptables rules to nftables.
- Linux Firewall Basics Linux firewalls control which network traffic is allowed in and out of your system. This guide covers the concepts, ufw for simple setups, and an introduction to the underlying nftables rules that power them all.
Related tools
- nftables Rule Builder Generate nftables rules and a stateful starter ruleset for the inet filter table.