Firewall & Security Hardening

Modern Firewall Management with nftables on RHEL-Based Systems (AlmaLinux, CentOS, Rocky Linux)

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (8 sections)

nftables is the packet-filtering framework in the Linux kernel that replaced iptables. On AlmaLinux, Rocky Linux and other RHEL-based systems it sits underneath firewalld, the default firewall tool, and you can also drive it directly with the nft command. This guide is for your own VPS or server with root access: it explains how the pieces fit, gives you a safe starting ruleset, and shows how to make it survive a reboot without locking yourself out.

Key takeaways

On AlmaLinux and Rocky Linux, firewalld is the default firewall and it already uses nftables underneath. For most servers, keep firewalld and use firewall-cmd. If you want to write nftables rules yourself, disable firewalld first, put your ruleset in /etc/sysconfig/nftables.conf, check it with nft -c -f, and enable the nftables service. Always keep SSH open and a rollback ready before you apply rules on a remote server.

This applies to your own VPS, not shared hosting

On Domain India cPanel, DirectAdmin and Webuzo shared hosting, the server firewall is ours and you can't change it. If you are blocked there, see I can't reach my server: have I been blocked?

1. How nftables, iptables and firewalld fit together

ToolWhat it isUse it when
nftables (nft)The kernel framework and its command-line toolYou want one hand-written ruleset file with full control
firewalld (firewall-cmd)The default RHEL firewall manager, using nftables as its backendYou want zones and services managed for you, as most servers do
iptablesThe older interface; on RHEL-based systems the iptables command is a compatibility layer that writes nftables rulesOnly for old scripts; new work should use nft or firewalld

The important rule: use one manager at a time. firewalld, a hand-written nftables service, CSF and some control panels each expect to own the ruleset. Running two of them means one silently overwrites the other after a reload or reboot. Docker also adds its own rules, so test container networking after any firewall change.

2. What nftables gives you

  • One syntax for IPv4 and IPv6. A table of family inet covers both, so you don't maintain two rule lists.
  • Sets and maps. Put many IP addresses or ports in one named set and match them with a single rule, instead of hundreds of lines.
  • Atomic loading. nft -f applies a whole file in one step, so there is never a half-applied ruleset.
  • Connection tracking. Allow replies to connections the server started with one ct state established,related rule.

3. The easy route: keep firewalld

If firewalld is running (systemctl status firewalld), manage it with firewall-cmd. It writes nftables rules for you.

bash
firewall-cmd --state
firewall-cmd --list-all
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --permanent --add-port=8443/tcp
firewall-cmd --reload

--permanent saves the change; --reload applies it. You can still look at the result with nft list ruleset, but don't edit firewalld's tables by hand, because the next reload replaces them.

4. Writing your own ruleset

If you prefer plain nftables, stop firewalld first so the two don't fight:

bash
systemctl disable --now firewalld
dnf install -y nftables

On RHEL-based systems the nftables service loads /etc/sysconfig/nftables.conf at boot. That file normally includes files from /etc/nftables/. Put a ruleset like this in /etc/nftables/main.nft:

nft
flush ruleset

table inet filter {
    set blocklist {
        type ipv4_addr
        flags interval
    }

    chain input {
        type filter hook input priority 0; policy drop;

        iif "lo" accept
        ct state established,related accept
        ct state invalid drop
        ip saddr @blocklist drop

        ip protocol icmp accept
        meta l4proto ipv6-icmp accept

        tcp dport 22 accept
        tcp dport { 80, 443 } accept
    }

    chain forward {
        type filter hook forward priority 0; policy drop;
    }

    chain output {
        type filter hook output priority 0; policy accept;
    }
}

Then add this line to /etc/sysconfig/nftables.conf:

nft
include "/etc/nftables/main.nft"

What the ruleset does: it drops everything incoming by default, allows loopback and replies, allows ping and the ICMPv6 messages IPv6 needs to work, and opens SSH, HTTP and HTTPS. flush ruleset at the top makes reloading the file replace the old rules instead of adding duplicates. It also removes rules Docker created, so restart Docker afterwards if you use it. Add the ports your own services need before you apply it.

5. Apply it without locking yourself out

A wrong rule on a remote server cuts your SSH session. Schedule an automatic rollback first, then apply.

  1. Save the current rules.
    { echo 'flush ruleset'; nft list ruleset; } > /root/nft-rollback.nft
  2. Check the new file's syntax.
    nft -c -f /etc/sysconfig/nftables.conf reports errors without applying anything.
  3. Arm a rollback.
    systemd-run --on-active=5min /usr/sbin/nft -f /root/nft-rollback.nft restores the old rules in five minutes unless you cancel it. Note the timer name it prints.
  4. Apply.
    nft -f /etc/sysconfig/nftables.conf
  5. Test from a new terminal.
    Open a second SSH session and load your website. Keep the first session open.
  6. Cancel the rollback and enable the service.
    systemctl stop run-XXXX.timer, using the timer name from step 3, then systemctl enable --now nftables.

If you do lose access, use your VPS provider's console, which is not affected by the firewall, and run nft flush ruleset.

6. Everyday commands

bash
nft list ruleset                              # everything that is loaded
nft -a list chain inet filter input           # the chain, with rule handles
nft add rule inet filter input tcp dport 3000 accept
nft delete rule inet filter input handle 12   # remove by handle
nft add element inet filter blocklist { 203.0.113.9 }
nft delete element inet filter blocklist { 203.0.113.9 }

Changes made with nft add or nft delete are live at once but are lost on reboot. Put anything you want to keep in the ruleset file and reload it with nft -f. Use the -a flag to see handles: you delete a rule by its handle, not its position.

7. Good habits

One source of truth
Keep the ruleset in a file under version control or a backup, and change the file rather than the live rules.
Default drop, explicit allow
Open only the ports your services use, and review the list when you remove a service.
Keep SSH safe
Use SSH keys, and consider allowing port 22 only from fixed IPs you control. Fail2ban can add offending IPs to an nftables set.
Check after changes
Run nft list ruleset and test from outside after every change, and after package or Docker updates.

Debian and Ubuntu use the same nft syntax; there the service reads /etc/nftables.conf instead. CentOS Linux has reached end of life, so for a new server choose AlmaLinux or Rocky Linux.

8. Running this on Domain India

A Domain India VPS is self-managed with full root access, so the firewall is yours to design and run. You can choose AlmaLinux, Rocky Linux, Ubuntu or Debian when you order, and cPanel is not offered on a VPS. The card shows the live list price, excluding 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

For a UFW-based setup, see Setting up a firewall on your VPS, and for SSH hardening, the SSH security hardening checklist.

Does AlmaLinux use nftables or iptables?

nftables. firewalld is the default firewall manager on AlmaLinux and Rocky Linux and it uses nftables as its backend. The iptables command on these systems is a compatibility layer that writes nftables rules.

Can I run firewalld and my own nftables rules together?

It is not recommended. Each expects to own the ruleset, and a firewalld reload can replace rules you added by hand. Pick one: keep firewalld and use firewall-cmd, or disable firewalld and manage an nftables ruleset file.

Where does the nftables service load rules from on RHEL-based systems?

From /etc/sysconfig/nftables.conf, which usually includes files from /etc/nftables/. On Debian and Ubuntu the file is /etc/nftables.conf.

Why do my nft rules disappear after a reboot?

Rules added with nft add live only in memory. Save them in the ruleset file the nftables service loads, then run systemctl enable nftables so it loads the file at boot.

How do I delete a single nftables rule?

List the chain with handles using nft -a list chain inet filter input, then run nft delete rule inet filter input handle followed by the number shown.

Can I use nftables on Domain India shared hosting?

No. On shared hosting the server firewall is managed by Domain India and customers can't change it. nftables applies to your own VPS or server.

Ready to run your own firewall? Compare VPS plans, or if you're on shared hosting and blocked, open a ticket with your public IP.

A server where the firewall is yours

Self-managed KVM VPS with full root access and your choice of Linux, so you can run nftables, firewalld or any tool you prefer.

See VPS plans

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
nftables on AlmaLinux and Rocky Linux: VPS Firewall