Network

The nft command

Manages the nftables firewall: creates modern rules (replaces iptables).

Syntax

nft [list ruleset | add rule ... | flush ruleset]

Copy-ready examples

$ sudo nft list rulesetShow the rules
$ sudo nft add rule inet filter input tcp dport 22 acceptAllow SSH

You can try them in the browser terminal: it does not touch your computer.

Typical mistakes

  • Needs sudo. The filter chain is usually inet filter input.

Related commands

FAQ

Learn to actually use it

The basic Linux course takes you from zero to console fluency with 24 self-grading lessons.

Start the free course