How to Configure a Linux Firewall Using Nftables with Tables, Chains, and Sets on Ubuntu Server

Learning how to configure a Linux firewall using nftables with tables, chains, and sets on Ubuntu Server is one of the most valuable skills you can add to your server administration toolkit. Nftables is the modern replacement for iptables. It ships with Ubuntu 20.04 and later by default. It offers a cleaner syntax, better performance, and a unified framework for filtering both IPv4 and IPv6 traffic. In this tutorial, you’ll learn how to install nftables, create tables and chains, define rules, and use sets to manage IP address groups efficiently. By the end, you’ll have a working firewall configuration that protects your Ubuntu server from unwanted traffic. Whether you’re securing a VPS, a dedicated server, or a home lab machine, this guide walks you through every step clearly and practically.

Prerequisites and Requirements for Configuring Nftables on Ubuntu

Before you start, make sure you have the following in place.

System Requirements:

  • Ubuntu Server 20.04 or later (22.04 LTS recommended)
  • Root or sudo access to the server
  • A basic understanding of networking concepts like ports and protocols
  • SSH access to your server (keep this session open throughout)

Estimated Time: 30–45 minutes

Important Warning: Misconfiguring a firewall can lock you out of your server. Always keep an active SSH session open while testing rules. If you’re working on a cloud VPS, check whether your provider offers a web-based console for emergency access. You should also know your server’s public IP address before you begin. Run curl ifconfig.me to find it quickly.

You don’t need prior experience with iptables. Nftables has its own syntax. Starting fresh is actually easier than migrating from iptables habits. Check the official nftables documentation if you want to explore advanced features beyond this tutorial.

How to Configure a Linux Firewall Using Nftables: Tables, Chains, and Rules

See also: How to Create and Configure Custom Systemd Services on Linux

Follow these steps carefully. Each step builds on the previous one.

Step 1: Install and Enable Nftables

First, update your package list and install nftables.

sudo apt update
sudo apt install nftables -y

Now enable and start the nftables service.

sudo systemctl enable nftables
sudo systemctl start nftables

Verify it’s running with sudo systemctl status nftables. You should see “active (running)” in the output.

Step 2: Check the Current Ruleset

Before writing any rules, check what’s already loaded.

sudo nft list ruleset

On a fresh Ubuntu install, this will return an empty ruleset. That’s expected.

Step 3: Create the Main Configuration File

Nftables loads rules from /etc/nftables.conf by default. Open it for editing.

sudo nano /etc/nftables.conf

Clear the existing content and start with this base structure.

#!/usr/sbin/nft -f

flush ruleset

table inet filter {

  chain input {
    type filter hook input priority 0; policy drop;
  }

  chain forward {
    type filter hook forward priority 0; policy drop;
  }

  chain output {
    type filter hook output priority 0; policy accept;
  }

}

This creates a table named filter using the inet family, which handles both IPv4 and IPv6. The input chain drops all incoming traffic by default. The output chain allows all outgoing traffic.

Step 4: Add Essential Rules to the Input Chain

A “drop all” policy is useless without exceptions. Add rules to allow legitimate traffic. Update your input chain to look like this.

chain input {
    type filter hook input priority 0; policy drop;

    # Allow established and related connections
    ct state established,related accept

    # Allow loopback interface
    iif lo accept

    # Drop invalid packets
    ct state invalid drop

    # Allow SSH (port 22)
    tcp dport 22 accept

    # Allow HTTP and HTTPS
    tcp dport { 80, 443 } accept

    # Allow ICMP (ping)
    ip protocol icmp accept
    ip6 nexthdr icmpv6 accept
  }

Save the file with Ctrl+O, then exit with Ctrl+X.

Step 5: Load the Configuration

Apply your new ruleset with this command.

sudo nft -f /etc/nftables.conf

Verify the rules loaded correctly.

sudo nft list ruleset

You should see your full table and chain structure in the output.

Step 6: Create a Set to Block IP Addresses

Sets are one of nftables’ most powerful features. A set lets you group IP addresses and reference them in a single rule. Add a named set inside your table, above the chains.

set blocklist {
    type ipv4_addr
    elements = { 192.168.1.100, 10.0.0.5 }
  }

Then add a rule at the top of your input chain to block those IPs.

ip saddr @blocklist drop

Your full /etc/nftables.conf should now look like this.

#!/usr/sbin/nft -f

flush ruleset

table inet filter {

  set blocklist {
    type ipv4_addr
    elements = { 192.168.1.100, 10.0.0.5 }
  }

  chain input {
    type filter hook input priority 0; policy drop;

    ip saddr @blocklist drop

    ct state established,related accept
    iif lo accept
    ct state invalid drop
    tcp dport 22 accept
    tcp dport { 80, 443 } accept
    ip protocol icmp accept
    ip6 nexthdr icmpv6 accept
  }

  chain forward {
    type filter hook forward priority 0; policy drop;
  }

  chain output {
    type filter hook output priority 0; policy accept;
  }

}

Reload the ruleset with sudo nft -f /etc/nftables.conf.

Step 7: Add IPs to a Set Dynamically

You don’t have to edit the config file every time. Add an IP to your blocklist on the fly.

sudo nft add element inet filter blocklist { 203.0.113.50 }

This takes effect immediately without reloading the entire ruleset.

Step 8: Save and Persist Rules Across Reboots

The nftables service loads /etc/nftables.conf automatically on boot. Since you’ve already written your rules there, they’ll persist. Confirm by restarting the service.

sudo systemctl restart nftables
sudo nft list ruleset

Your rules should still be present after the restart. For more details on persistent configurations, see the Ubuntu Server firewall documentation.

Troubleshooting Common Nftables Configuration Issues

Even experienced admins run into problems. Here are the most common ones.

Problem: Locked out of SSH after applying rules
This happens when you forget to allow port 22. If you have console access, log in and run sudo nft flush ruleset to clear all rules. Then re-add SSH before setting a drop policy.

Problem: Rules don’t persist after reboot
Check that the nftables service is enabled. Run sudo systemctl enable nftables. Also confirm your rules are saved in /etc/nftables.conf and not just applied live.

Problem: Syntax errors when loading the config
Run sudo nft -c -f /etc/nftables.conf to check for syntax errors without applying the rules. The -c flag runs a dry-run validation. Fix any reported errors before reloading.

Problem: IPv6 traffic not being filtered
Make sure you’re using the inet family for your table. Tables using ip only handle IPv4. The inet family covers both protocols in one ruleset.

Tip: Always test your firewall from a second machine or terminal window. Don’t close your original SSH session until you’ve confirmed access still works.

Conclusion: What You’ve Accomplished

You now know how to configure a Linux firewall using nftables with tables, chains, and sets on Ubuntu Server. You’ve installed nftables, written a base ruleset with a drop-all policy, added exceptions for SSH and web traffic, and used sets to manage blocked IPs efficiently. These fundamentals give you a solid, working firewall that you can expand as your needs grow. From here, you can explore rate limiting with nftables meters, logging dropped packets, or building more complex chain structures for multi-homed servers. Nftables scales well from simple VPS setups to complex enterprise environments. Keep your ruleset under version control so

Similar Posts