The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
List the rulesetsudo nft list rulesetView examples
Show rule handlessudo nft --handle list rulesetView examples
Back up active rulessudo nft list ruleset > ./nftables.backupView examples
Validate a filesudo nft --check --file ./nftables.confView examples
Load a batchsudo nft --file ./nftables.confView examples
Create an inet tablesudo nft add table inet filterView examples
Create an input base chainsudo nft \ 'add chain inet filter input { type filter hook input priority filter; policy drop; }'View examples
Allow established trafficsudo nft add rule inet filter input ct state \ established,related acceptView examples
Allow loopbacksudo nft add rule inet filter input iifname lo acceptView examples
Allow TCP servicesudo nft add rule inet filter input tcp dport 22 ct \ state new accept comment 'management SSH'View examples
Create an address setsudo nft \ 'add set inet filter admins { type ipv4_addr; flags interval; }'View examples
Count rule matchessudo nft add rule inet filter input tcp dport 443 \ counter acceptView examples
Monitor tracessudo nft monitor traceView examples
Monitor ruleset eventssudo nft monitor rulesetView examples

nftables is a stateful packet-filtering framework whose rules can immediately disrupt local or remote access. Inspect the complete active ruleset and management path, preserve a verified rollback, validate files before loading, use named tables and comments, and test from a separate session before making changes persistent.

Step by step

Detailed examples

01

Capture the active policy before touching it

Rules may be managed by a distribution firewall service, container runtime, or configuration system. Record the full ruleset with handles and identify its owner before manual changes. Store backups with restricted permissions because rules can reveal network topology and service exposure.

Audit and capture active state
sudo nft --handle list ruleset
sudo nft list ruleset > ./nftables.backup
sudo systemctl status nftables --no-pager
Back to quick reference ↑
02

Validate a complete batch and retain out-of-band recovery

nft -c checks commands without applying them; -f submits a file in one batch so a failing command prevents partial batch application. Semantic mistakes can still pass validation. Keep another administrative session and a timed or console rollback when changing remote ingress.

Check before an authorized load
sudo nft --check --file ./nftables.conf
# Review the exact diff and rollback path before running:
# sudo nft --file ./nftables.conf
Back to quick reference ↑
03

Understand hooks, priority, and policy

Tables contain chains; base chains attach to hooks such as input, forward, and output with a type and priority. Regular chains are reached by jump or goto. Multiple base chains may share a hook, so a rule in one table is not the whole policy. inet families can handle IPv4 and IPv6 together.

Minimal declarative skeleton
table inet filter {
  chain input {
    type filter hook input priority filter; policy drop;
  }
  chain forward {
    type filter hook forward priority filter; policy drop;
  }
}
Back to quick reference ↑
04

Allow return traffic and management before default drop

Connection tracking identifies established and related traffic. Loopback and required management traffic normally need explicit acceptance before a drop policy. Interface names, address families, service ports, and source restrictions must reflect the real host; test both IPv4 and IPv6.

Ordered input policy fragment
ct state invalid drop
ct state established,related accept
iifname "lo" accept
ip saddr 192.0.2.0/24 tcp dport 22 ct state new accept comment "management SSH"
tcp dport 443 ct state new counter accept
Back to quick reference ↑
05

Use sets for changing membership and counters for evidence

Sets keep address or port membership separate from rule logic and can support intervals and timeouts. Named counters provide reusable telemetry; anonymous counters stay with one rule. Counter hits show matching traffic, not whether an application completed successfully.

Address-set rule
set admins {
  type ipv4_addr
  flags interval
  elements = { 192.0.2.0/24, 198.51.100.8 }
}
ip saddr @admins tcp dport 22 counter accept
Back to quick reference ↑
06

Trace narrowly and persist through one owner

Tracing requires a rule that sets nftrace, then nft monitor trace observes matching traversal; broad tracing can be noisy. Runtime changes vanish after reboot unless the system's nftables configuration service saves and loads them. Do not let two firewall managers overwrite each other.

Observe ruleset changes safely
sudo nft monitor ruleset
# In a separate diagnostic workflow, trace only a narrowly matched packet set:
# sudo nft monitor trace
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Netfilter Projectnft(8)netfilter.org
  2. Netfilter Projectnftables wikiwiki.nftables.org
  3. Netfilter ProjectNetfilter nftables projectnetfilter.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback