nftables
Notes
Examples
sudo nft add table ip <RULE_NAME>
sudo nft add chain ip <RULE_NAME> FILTER { type filter hook input priority 0 \; policy accept \; }
sudo nft add rule ip <RULE_NAME> FILTER tcp sport {ssh, telnet, 3389, 6010-6050} ct state {new, established} accept
sudo nft list ruleset
sudo nft add chain ip <RULE_NAME> FILTER1 { type filter hook output priority 0 \; policy accept \; }
sudo nft list ruleset
sudo nft add rule ip <RULE_NAME> FILTER1 tcp sport {ssh, telnet, 3389, 6010-6050} ct state {new, established} accept
sudo nft add rule ip <RULE_NAME> FILTER tcp dport {ssh, telnet, 3389, 6010-6050} ct state {new, established} accept
sudo nft add rule ip <RULE_NAME> FILTER1 tcp dport {ssh, telnet, 3389, 6010-6050} ct state {new, established} acceptNFTable Families
CREATION OF HOOKS
1. CREATE THE TABLE
2. CREATE THE BASE CHAIN
3. CREATE A RULE IN THE CHAIN
MODIFY NFTABLES
Save/Load nftables
Filter for SSH Traffic (Example)
Rules
NAT, PAT, and NAT Port Forwarding (Examples)
Last updated