nftables is the packet-filtering framework in the Linux kernel that replaced iptables. On AlmaLinux, Rocky Linux and other RHEL-based systems it sits underneath firewalld, the default firewall tool, and you can also drive it directly with the nft command. This guide is for your own VPS or server with root access: it explains how the pieces fit, gives you a safe starting ruleset, and shows how to make it survive a reboot without locking yourself out.
On AlmaLinux and Rocky Linux, firewalld is the default firewall and it already uses nftables underneath. For most servers, keep firewalld and use firewall-cmd. If you want to write nftables rules yourself, disable firewalld first, put your ruleset in /etc/sysconfig/nftables.conf, check it with nft -c -f, and enable the nftables service. Always keep SSH open and a rollback ready before you apply rules on a remote server.
On Domain India cPanel, DirectAdmin and Webuzo shared hosting, the server firewall is ours and you can't change it. If you are blocked there, see I can't reach my server: have I been blocked?
1. How nftables, iptables and firewalld fit together
| Tool | What it is | Use it when |
|---|---|---|
nftables (nft) | The kernel framework and its command-line tool | You want one hand-written ruleset file with full control |
firewalld (firewall-cmd) | The default RHEL firewall manager, using nftables as its backend | You want zones and services managed for you, as most servers do |
| iptables | The older interface; on RHEL-based systems the iptables command is a compatibility layer that writes nftables rules | Only for old scripts; new work should use nft or firewalld |
The important rule: use one manager at a time. firewalld, a hand-written nftables service, CSF and some control panels each expect to own the ruleset. Running two of them means one silently overwrites the other after a reload or reboot. Docker also adds its own rules, so test container networking after any firewall change.
2. What nftables gives you
- One syntax for IPv4 and IPv6. A table of family
inetcovers both, so you don't maintain two rule lists. - Sets and maps. Put many IP addresses or ports in one named set and match them with a single rule, instead of hundreds of lines.
- Atomic loading.
nft -fapplies a whole file in one step, so there is never a half-applied ruleset. - Connection tracking. Allow replies to connections the server started with one
ct state established,relatedrule.
3. The easy route: keep firewalld
If firewalld is running (systemctl status firewalld), manage it with firewall-cmd. It writes nftables rules for you.
firewall-cmd --state
firewall-cmd --list-all
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --permanent --add-port=8443/tcp
firewall-cmd --reload--permanent saves the change; --reload applies it. You can still look at the result with nft list ruleset, but don't edit firewalld's tables by hand, because the next reload replaces them.
4. Writing your own ruleset
If you prefer plain nftables, stop firewalld first so the two don't fight:
systemctl disable --now firewalld
dnf install -y nftablesOn RHEL-based systems the nftables service loads /etc/sysconfig/nftables.conf at boot. That file normally includes files from /etc/nftables/. Put a ruleset like this in /etc/nftables/main.nft:
flush ruleset
table inet filter {
set blocklist {
type ipv4_addr
flags interval
}
chain input {
type filter hook input priority 0; policy drop;
iif "lo" accept
ct state established,related accept
ct state invalid drop
ip saddr @blocklist drop
ip protocol icmp accept
meta l4proto ipv6-icmp accept
tcp dport 22 accept
tcp dport { 80, 443 } accept
}
chain forward {
type filter hook forward priority 0; policy drop;
}
chain output {
type filter hook output priority 0; policy accept;
}
}Then add this line to /etc/sysconfig/nftables.conf:
include "/etc/nftables/main.nft"What the ruleset does: it drops everything incoming by default, allows loopback and replies, allows ping and the ICMPv6 messages IPv6 needs to work, and opens SSH, HTTP and HTTPS. flush ruleset at the top makes reloading the file replace the old rules instead of adding duplicates. It also removes rules Docker created, so restart Docker afterwards if you use it. Add the ports your own services need before you apply it.
5. Apply it without locking yourself out
A wrong rule on a remote server cuts your SSH session. Schedule an automatic rollback first, then apply.
- Save the current rules.
{ echo 'flush ruleset'; nft list ruleset; } > /root/nft-rollback.nft - Check the new file's syntax.
nft -c -f /etc/sysconfig/nftables.confreports errors without applying anything. - Arm a rollback.
systemd-run --on-active=5min /usr/sbin/nft -f /root/nft-rollback.nftrestores the old rules in five minutes unless you cancel it. Note the timer name it prints. - Apply.
nft -f /etc/sysconfig/nftables.conf - Test from a new terminal.Open a second SSH session and load your website. Keep the first session open.
- Cancel the rollback and enable the service.
systemctl stop run-XXXX.timer, using the timer name from step 3, thensystemctl enable --now nftables.
If you do lose access, use your VPS provider's console, which is not affected by the firewall, and run nft flush ruleset.
6. Everyday commands
nft list ruleset # everything that is loaded
nft -a list chain inet filter input # the chain, with rule handles
nft add rule inet filter input tcp dport 3000 accept
nft delete rule inet filter input handle 12 # remove by handle
nft add element inet filter blocklist { 203.0.113.9 }
nft delete element inet filter blocklist { 203.0.113.9 }Changes made with nft add or nft delete are live at once but are lost on reboot. Put anything you want to keep in the ruleset file and reload it with nft -f. Use the -a flag to see handles: you delete a rule by its handle, not its position.
7. Good habits
nft list ruleset and test from outside after every change, and after package or Docker updates.Debian and Ubuntu use the same nft syntax; there the service reads /etc/nftables.conf instead. CentOS Linux has reached end of life, so for a new server choose AlmaLinux or Rocky Linux.
8. Running this on Domain India
A Domain India VPS is self-managed with full root access, so the firewall is yours to design and run. You can choose AlmaLinux, Rocky Linux, Ubuntu or Debian when you order, and cPanel is not offered on a VPS. The card shows the live list price, excluding 18% GST.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
For a UFW-based setup, see Setting up a firewall on your VPS, and for SSH hardening, the SSH security hardening checklist.
Does AlmaLinux use nftables or iptables?
nftables. firewalld is the default firewall manager on AlmaLinux and Rocky Linux and it uses nftables as its backend. The iptables command on these systems is a compatibility layer that writes nftables rules.
Can I run firewalld and my own nftables rules together?
It is not recommended. Each expects to own the ruleset, and a firewalld reload can replace rules you added by hand. Pick one: keep firewalld and use firewall-cmd, or disable firewalld and manage an nftables ruleset file.
Where does the nftables service load rules from on RHEL-based systems?
From /etc/sysconfig/nftables.conf, which usually includes files from /etc/nftables/. On Debian and Ubuntu the file is /etc/nftables.conf.
Why do my nft rules disappear after a reboot?
Rules added with nft add live only in memory. Save them in the ruleset file the nftables service loads, then run systemctl enable nftables so it loads the file at boot.
How do I delete a single nftables rule?
List the chain with handles using nft -a list chain inet filter input, then run nft delete rule inet filter input handle followed by the number shown.
Can I use nftables on Domain India shared hosting?
No. On shared hosting the server firewall is managed by Domain India and customers can't change it. nftables applies to your own VPS or server.
Ready to run your own firewall? Compare VPS plans, or if you're on shared hosting and blocked, open a ticket with your public IP.
Self-managed KVM VPS with full root access and your choice of Linux, so you can run nftables, firewalld or any tool you prefer.
See VPS plans