nftables on Linux: Basic Firewall Rules (SSH, HTTP/HTTPS) That Persist

nftables linux firewall - custom-nft-featured.png

nftables is the modern netfilter frontend on most current distributions. iptables often talks to the same kernel rules through a compatibility layer,
but new rules are clearer when written directly in nft syntax.

If you prefer a higher-level tool, start with UFW — on many releases it already programs nftables underneath.
Use raw nft when you need explicit, portable rules in Git.

nftables Building Blocks

Rules live in tables (address families like inet), grouped into chains attached to hooks such as input.

bashshow rules
sudo nft list ruleset
nft structure
table chain rule

Create a Filter Table

A minimal host firewall uses an input chain with a default policy of drop after explicit allows.

nft/etc/nftables.conf (minimal skeleton)
table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;
  }
}
table inet filter
input chain

Allow SSH and Web Traffic

Permit established flows first, then management and public services.

nftexample rules
ct state established,related accept
iif lo accept
tcp dport 22 accept
tcp dport { 80, 443 } accept
icmp type echo-request accept
allow rules
ssh http https

Persist and Enable

Save the live ruleset or maintain /etc/nftables.conf and enable the service.

bashenable
sudo nft -f /etc/nftables.conf
sudo systemctl enable --now nftables
persist
nftables.service

Avoid Lockouts

Keep an open SSH session while testing. Add allow rules before switching policy to drop.

WarningAlways allow loopback (iif lo accept) and established connections.
safe testing
second session

UFW, firewalld, and Docker

Only one manager should own the ruleset. Docker publishes ports with its own iptables/nft interactions.

NoteSee our Docker install guide for UFW/Docker publishing caveats.
one manager
UFW vs raw nft

Verify Listeners and Rules

Confirm services listen where you expect, then test from a client.

bashchecks
sudo nft list chain inet filter input
sudo ss -tlnp
verify
nft and ss

Quick Reference

  • Policy drop after explicit accept rules
  • Allow established,related and lo
  • Test with a spare SSH session open

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.