Nftables

nftables is Linux’s modern firewall and packet classification framework.

Why it matters

  • Consolidates filtering, NAT, and packet mangling in one framework.
  • Simplifies firewall rule management across IPv4 and IPv6.
  • Improves maintainability compared to legacy rule stacks.

Operational use

  • Define base chains for input/output/forward policies.
  • Version and review rulesets as infrastructure code.
  • Combine with service-level hardening and monitoring.