nftables: Basic Rule Set
All commands were verified on Debian/Ubuntu with the nftables package and on RHEL/CentOS 8+. On older systems you may need apt install nftables or yum install nftables.
nftables replaced iptables, but documentation for a basic rule set is often scattered. Here is the reference I use when bringing up a firewall on a new host.
Creating the inet filter table
The inet family table unifies IPv4 and IPv6 under a single namespace. This is the preferred approach when both stacks are active on the host.
If the table already exists the command returns an error. To avoid duplication when a script is re-run:
To wipe the current rule set before loading your own:
flush ruleset removes all rules instantly. On a production machine run this only from the console, not over a remote session without a fallback.
Input and forward chains
Chains bind to a table and define the interception point for traffic. A basic firewall needs input (traffic destined for the host itself) and forward (traffic passing through the host).
Key components inside the curly braces:
| Component | Value |
|---|---|
type filter | Chain type, standard for packet filtering |
hook input / hook forward | Interception point in the network stack |
priority 0 | Processing priority |
policy drop | Default policy — drop unmatched packets |
The syntax requires escaping semicolons inside the string or using single quotes as shown above.
If you need to allow established connections, add an output chain with policy accept or use connection tracking in your input rules.
Basic rules for input
With a chain set to policy drop, you must explicitly permit the traffic you need. A typical minimum:
Each rule appends to the end of the chain. Order matters: accept rules for loopback and established traffic should come before rules with narrower criteria.
To log dropped packets before the drop policy (optional but useful for diagnostics):
Logging adds overhead. On high-throughput interfaces use a rate limit: limit rate 10/second.
Basic rules for forward
The forward chain is needed when the host acts as a router or NAT gateway. A minimum setup:
If the host does not perform routing, leave forward with policy drop and no additional rules.
To enable IP forwarding at the kernel level (if not already done):
Viewing and managing rules
After setup, verify the current configuration:
list ruleset outputs the full config, which you can save and reuse as a boot script.
Deleting a specific rule by handle within a chain:
The handle number appears in the output of nft list ruleset -a.
To delete an entire chain:
A chain can only be deleted when it is empty. To remove a table completely, delete all chains inside it first.
Saving rules to a file for boot-time loading:
On systems with systemd, enable auto-start:
If /etc/nftables.conf does not exist or is empty, the service will not load any rules. Create the file manually before enabling the service.