nft
Administration tool for nftables (successor to iptables)
Overview
nftables is the modern replacement for iptables, ip6tables, arptables, and ebtables. It provides a single framework for packet classification.
Syntax
nft [options] [commands]Common Options
list rulesetList all rules in all tables.
add table family nameAdd a new table.
add chainAdd a new chain to a table.
add ruleAdd a new rule to a chain.
delete ruleDelete a rule from a chain.
flush rulesetDelete all rules.
-f, --file filenameRead input from specified file.
-i, --interactiveRead input from an interactive readline CLI.
Examples
Display all current rules.
Create a new table named "filter" for inet (IPv4/IPv6) family.
Create an input chain in the filter table.
Allow SSH on port 22.
Allow HTTP and HTTPS.
Allow established connections.
Drop all other incoming traffic.
Load rules from configuration file.
Remove all rules and tables.