Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Linux firewall examples with nftables and iptables

From Tech-Wiki


Practical Linux firewall examples for modern nftables systems and for environments that still expose the iptables command syntax.

ⓘ
Validation status
Reviewed against the Netfilter nftables migration documentation on 27 September 2026.
!
Remote firewall changes can lock you out
When changing firewall policy over SSH, keep an independent recovery path and validate the new rules before applying a default-drop policy. Distribution-specific firewall managers such as firewalld or ufw may also own the active ruleset.

nftables and iptables today

The Netfilter project describes the older xtables/legacy framework as legacy and provides migration tools for moving rules to nftables.

Some Linux distributions still provide the familiar iptables command while using the nftables kernel backend. Do not assume that seeing an iptables binary means the system is using the legacy x_tables backend.

Check the installed tools and active ruleset before making changes.

>_Inspect firewall tooling
iptables --version
nft list ruleset

Back up the current rules

If an iptables-compatible ruleset exists:

>_Export the current iptables rules
iptables-save > iptables-backup.txt

For nftables:

>_Export the current nftables ruleset
nft list ruleset > nftables-backup.nft

Store the backup somewhere that remains accessible if network connectivity is lost.

Translate an iptables rule

The Netfilter project provides iptables-translate to show the nftables equivalent of an iptables command.

>_Translate an SSH rule
iptables-translate -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT

This is useful when rationalising old scripts before creating the final nftables ruleset.

Example nftables test table

The following example creates a separate demonstration table and keeps the input policy at accept, which avoids silently turning a documentation example into a complete host firewall.

>_Create a small nftables demonstration ruleset
nft add table inet twdemo
nft 'add chain inet twdemo input { type filter hook input priority 10; policy accept; }'
nft add rule inet twdemo input ct state established,related accept
nft add rule inet twdemo input ip saddr 192.0.2.0/24 tcp dport 22 accept

Inspect the result:

>_Show the demonstration table
nft list table inet twdemo

Remove it when finished:

>_Remove the demonstration table
nft delete table inet twdemo

Legacy iptables syntax examples

For systems intentionally using iptables-compatible syntax, use conntrack state matching rather than copying very old -m state examples.

>_Allow established traffic and SSH from a management subnet
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp -s 192.0.2.0/24 --dport 22 -m conntrack --ctstate NEW -j ACCEPT
>_Drop traffic from a specific source
iptables -A INPUT -s 198.51.100.25 -j DROP

These examples are individual rules, not a complete firewall policy.

Migrating a complete ruleset

The Netfilter migration tooling can translate an exported iptables ruleset:

>_Translate an iptables-save file
iptables-restore-translate -f iptables-backup.txt > ruleset.nft

Review the translated file carefully before loading it.

!
Do not operate legacy and nftables policies blindly in parallel
The Netfilter project warns that mixing legacy x_tables rules and nftables rules can produce unexpected results. Understand which backend and firewall manager owns the host policy before changing it.

Official references

See also