Nftables
nftables is Linux’s modern firewall and packet classification framework.
Why it matters
- Consolidates filtering, NAT, and packet mangling in one framework.
- Simplifies firewall rule management across IPv4 and IPv6.
- Improves maintainability compared to legacy rule stacks.
Operational use
- Define base chains for input/output/forward policies.
- Version and review rulesets as infrastructure code.
- Combine with service-level hardening and monitoring.