Nftables hardening rules and good practices

1 gladiatr72 1 6/4/2025, 4:05:22 PM samuel.forestier.app ↗

Comments (1)

gladiatr72 · 2d ago
A good blog post for bootstrapping a tight nftables config. It comes with useful examples and a list of references and for-further-reading links. All links but one (the first listed at the bottom of the page) are alive. The one dead link is available via archive.org.

To quote the blog's author: As it should be considered as the-way-of-managing-Netfilter since 2016, I was pretty frustrated not to find any “hardening” guide for it on the Web, so here is one!

Originally from 2020 with updates in 2023. It is still the best in show in 2025 if you are looking for a non-hello-world introduction to nftables.

NOTE: presumes existing knowledge of linux networking/routing bits