Welcome to My Blog 👋

Java, Spring Framework, Microservices, Docker, Kubernetes, AWS and Others 🚀
Follow Me

Nftables, ağ paketlerinin, ağ datagramlarının, ağ çerçevelerinin filtrelenmesini ve sınıflandırılmasını sağlayan Linux çekirdeğinin bir alt sistemidir. 
Linux çekirdeği 3.13'te çalışır. 
Iptables'in yeni sürümü olarak görülebilir ancak söz dizimi iptables'tan farklıdır. Aynı zamanda iptables komutlarının da çalıştırılmasına izin verilen bir uyumluluk modu vardır. 
En önemli yeniliği kural sayısını çok fazla azaltmasıdır.

Nftables Kurulumu
  • sudo apt-get install nftables
komutu ile kurulum gerçekleştirilir.

Nfrables Tablo(Table), Zincir(Chain), Kural(Rule) Kavramları
  • Tablo, belirli bir semantik içermeyen bir zincirler konteynırını ifade eder.
  • Bir tablodaki zincir, bir kurallar konteynırını ifade eder.
  • Kural, bir zincir içinde yapılandırılacak bir eylemi ifade eder.

Nftables Tablo İşlemleri

Tablo Oluşturmak, Silmek, Flush İşlemleri
  • nft (add | delete | flush) table [<family>] <isim>
Var Olan Tabloları Listeletmek
  • nft list tables [<family>]
  • nft list table [<family>] <name> [-n] [-a]
Family bu tablo türlerinden birine karşılık gelir: ip, arp, ip6, bridge, inet, netdev.
-n argümanı, adresleri ve diğer bilgileri gösterir. -a argümanı, handle'ı görüntülemek için kullanılır.

Nftables Zincir İşlemleri

Zincir Ekleme ve Oluşturma
  • nft (add | create) chain [<family>] <table> <name> [ { type <type> hook <hook> [device <device>] priority <priority> \; [policy <policy> \;] } ] 
Zincir Silme ve Var Olan Zicirleri Listeleme
  • nft (delete | list | flush) chain [<family>] <table> <name> 
Zincirin İsmini Değiştirme
  • nft rename chain [<family>] <table> <name> <newname>

type parametresi oluşturulacak zincirin türünü belirtir.
  • filter : Arp, bridge, IP, IPv6 ve inet tarafından desteklenir.
  • route : Çıkış işlemleri için kullanılır. IP VE IPv6 tarafından desteklenir.
  • nat : Ağ adresi çevirisi gerçekleştirmek için kullanılır. IP ve IPv6 tarafından desteklenir.
hook parametresi çekirdekte işlenecek paketlerin aşamasını belirtir.
  • IP, IPv6 ve inet için hook, prerouting, input, forward, output, postrouting.
  • Arp için hook, input, output.
  • Bridge için hook, köprü aygıtlarını geçen ethernet paketlerini yönetir.
  • Netdev için hook, ingress.
priority, Zincirleri sipariş etmek veya bazı Netfilter işlemleri arasında ayarlamak için kullanılan bir numarayı belirtir. Olası değerler:
  • NF_IP_PRI_RAW (-300)
  • NF_IP_PRI_MANGLE (-150)
  • NF_IP_PRI_NAT_DST (-100)
  • NF_IP_PRI_NAT_SRC (100)
policy, parametresi zincirde ki paketlere ne yapılacağını belirtir. Olası değerler:
  • accept (Kabul Et)
  • drop (DÜşür)
  • queue (Kuyruk)
  • continue (Devam)
  • return (Geri Dön)

Nftables Kural İşlemleri

Kural Ekleme
  • nft add rule [<family>] <table> <chain> <matches> <statements> 
Araya Kural Ekleme
  • nft insert rule [<family>] <table> <chain> [position <position>] <matches> <statements> 
Kural Değiştirme
  • nft replace rule [<family>] <table> <chain> [handle <handle>] <matches> <statements> 
Kural Silme
  • nft delete rule [<family>] <table> <chain> [handle <handle>]
handle parametresi belirli bir kuralı tanımlayan dahili bir sayıdır.

position parametresi belirli bir handle'dan önce bir kural eklemek için kullanılan dahili bir sayıdır.

Matches Parametresi

ip match
dscp <value>
ip dscp cs1
ip dscp != cs1
ip dscp 0x38
ip dscp != 0x20
ip dscp {cs0, cs1, cs2, cs3, cs4, cs5, cs6, cs7, af11, af12, af13, af21, 
af22, af23, af31, af32, af33, af41, af42, af43, ef}
length <length>Total packet length
ip length 232
ip length != 233
ip length 333-435
ip length != 333-453
ip length { 333, 553, 673, 838}
id <id>IP ID
ip id 22
ip id != 233
ip id 33-45
ip id != 33-45
ip id { 33, 55, 67, 88 }
frag-off <value>Fragmentation offset
ip frag-off 222
ip frag-off != 233
ip frag-off 33-45
ip frag-off != 33-45
ip frag-off { 33, 55, 67, 88 }
ttl <ttl>Time to live
ip ttl 0
ip ttl 233
ip ttl 33-55
ip ttl != 45-50
ip ttl { 43, 53, 45 }
ip ttl { 33-55 }
protocol <protocol>Upper layer protocol
ip protocol tcp
ip protocol 6
ip protocol != tcp
ip protocol { icmp, esp, ah, comp, udp, udplite, tcp, dccp, sctp }
checksum <checksum>IP header checksum
ip checksum 13172
ip checksum 22
ip checksum != 233
ip checksum 33-45
ip checksum != 33-45
ip checksum { 33, 55, 67, 88 }
ip checksum { 33-55 }
saddr <ip source address>Source address
ip saddr
ip saddr !=
ip saddr ip daddr
ip saddr !=
ip saddr
ip saddr & 0xff == 1
ip saddr & <
daddr <ip destination address>Destination address
ip daddr
ip daddr !=
ip daddr
ip daddr
ip daddr
ip daddr
ip daddr !=
ip daddr { }
ip daddr {,, }
version <version>Ip Header version
ip version 4
hdrlength <header length>IP header length
ip hdrlength 0
ip hdrlength 15


ip6 match
dscp <value>
ip6 dscp cs1
ip6 dscp != cs1
ip6 dscp 0x38
ip6 dscp != 0x20
ip6 dscp {cs0, cs1, cs2, cs3, cs4, cs5, cs6, cs7, af11, af12, af13, af21, af22, af23, af31, af32, af33, af41, af42, af43, ef}
flowlabel <label>Flow label
ip6 flowlabel 22
ip6 flowlabel != 233
ip6 flowlabel { 33, 55, 67, 88 }
ip6 flowlabel { 33-55 }
length <length>Payload length
ip6 length 232
ip6 length != 233
ip6 length 333-435
ip6 length != 333-453
ip6 length { 333, 553, 673, 838}
nexthdr <header>Next header type (Upper layer protocol number)
ip6 nexthdr {esp, udp, ah, comp, udplite, tcp, dccp, sctp, icmpv6}
ip6 nexthdr esp
ip6 nexthdr != esp
ip6 nexthdr { 33-44 }
ip6 nexthdr 33-44
ip6 nexthdr != 33-44
hoplimit <hoplimit>Hop limit
ip6 hoplimit 1
ip6 hoplimit != 233
ip6 hoplimit 33-45
ip6 hoplimit != 33-45
ip6 hoplimit {33, 55, 67, 88}
ip6 hoplimit {33-55}
saddr <ip source address>Source Address
ip6 saddr 1234:1234:1234:1234:1234:1234:1234:1234
ip6 saddr ::1234:1234:1234:1234:1234:1234:1234
ip6 saddr ::/64
ip6 saddr ::1 ip6 daddr ::2
daddr <ip destination address>Destination Address
ip6 daddr 1234:1234:1234:1234:1234:1234:1234:1234
ip6 daddr != ::1234:1234:1234:1234:1234:1234:1234-1234:1234::1234:1234:1234:1234:1234
version <version>IP header version
ip6 version 6


tcp match
dport <destination port>Destination port
tcp dport 22
tcp dport != 33-45
tcp dport { 33-55 }
tcp dport {telnet, http, https }
tcp dport vmap { 22 : accept, 23 : drop }
tcp dport vmap { 25:accept, 28:drop }
sport < source port>Source port
tcp sport 22
tcp sport != 33-45
tcp sport { 33, 55, 67, 88}
tcp sport { 33-55}
tcp sport vmap { 25:accept, 28:drop }
tcp sport 1024 tcp dport 22
sequence <value>Sequence number
tcp sequence 22
tcp sequence != 33-45
ackseq <value>Acknowledgement number
tcp ackseq 22
tcp ackseq != 33-45
tcp ackseq { 33, 55, 67, 88 }
tcp ackseq { 33-55 }
flags <flags>TCP flags
tcp flags { fin, syn, rst, psh, ack, urg, ecn, cwr}
tcp flags cwr
tcp flags != cwr
window <value>Window
tcp window 22
tcp window != 33-45
tcp window { 33, 55, 67, 88 }
tcp window { 33-55 }
checksum <checksum>IP header checksum
tcp checksum 22
tcp checksum != 33-45
tcp checksum { 33, 55, 67, 88 }
tcp checksum { 33-55 }
urgptr <pointer>Urgent pointer
tcp urgptr 22
tcp urgptr != 33-45
tcp urgptr { 33, 55, 67, 88 }
doff <offset>Data offset
tcp doff 8


udp match
dport <destination port>Destination port
udp dport 22
udp dport != 33-45
udp dport { 33-55 }
udp dport {telnet, http, https }
udp dport vmap { 22 : accept, 23 : drop }
udp dport vmap { 25:accept, 28:drop }
sport < source port>Source port
udp sport 22
udp sport != 33-45
udp sport { 33, 55, 67, 88}
udp sport { 33-55}
udp sport vmap { 25:accept, 28:drop }
udp sport 1024 tcp dport 22
length <length>Total packet length
udp length 6666
udp length != 50-65
udp length { 50, 65 }
udp length { 35-50 }
checksum <checksum>UDP checksum
udp checksum 22
udp checksum != 33-45
udp checksum { 33, 55, 67, 88 }
udp checksum { 33-55 }


udplite match
dport <destination port>Destination port
udplite dport 22
udplite dport != 33-45
udplite dport { 33-55 }
udplite dport {telnet, http, https }
udplite dport vmap { 22 : accept, 23 : drop }
udplite dport vmap { 25:accept, 28:drop }
sport < source port>Source port
udplite sport 22
udplite sport != 33-45
udplite sport { 33, 55, 67, 88}
udplite sport { 33-55}
udplite sport vmap { 25:accept, 28:drop }
udplite sport 1024 tcp dport 22
checksum <checksum>Checksum
udplite checksum 22
udplite checksum != 33-45
udplite checksum { 33, 55, 67, 88 }
udplite checksum { 33-55 }


sctp match
dport <destination port>Destination port
sctp dport 22
sctp dport != 33-45
sctp dport { 33-55 }
sctp dport {telnet, http, https }
sctp dport vmap { 22 : accept, 23 : drop }
sctp dport vmap { 25:accept, 28:drop }
sport < source port>Source port
sctp sport 22
sctp sport != 33-45
sctp sport { 33, 55, 67, 88}
sctp sport { 33-55}
sctp sport vmap { 25:accept, 28:drop }
sctp sport 1024 tcp dport 22
checksum <checksum>Checksum
sctp checksum 22
sctp checksum != 33-45
sctp checksum { 33, 55, 67, 88 }
sctp checksum { 33-55 }
vtag <tag>Verification tag
sctp vtag 22
sctp vtag != 33-45
sctp vtag { 33, 55, 67, 88 }
sctp vtag { 33-55 }


dccp match
dport <destination port>Destination port
dccp dport 22
dccp dport != 33-45
dccp dport { 33-55 }
dccp dport {telnet, http, https }
dccp dport vmap { 22 : accept, 23 : drop }
dccp dport vmap { 25:accept, 28:drop }
sport < source port>Source port
dccp sport 22
dccp sport != 33-45
dccp sport { 33, 55, 67, 88}
dccp sport { 33-55}
dccp sport vmap { 25:accept, 28:drop }
dccp sport 1024 tcp dport 22
type <type>Type of packet
dccp type {request, response, data, ack, dataack, closereq, close, reset, sync, syncack}
dccp type request
dccp type != request


ah match
hdrlength <length>AH header length
ah hdrlength 11-23
ah hdrlength != 11-23
ah hdrlength {11, 23, 44 }
reserved <value>
ah reserved 22
ah reserved != 33-45
ah reserved {23, 100 }
ah reserved { 33-55 }
spi <value>
ah spi 111
ah spi != 111-222
ah spi {111, 122 }
sequence <sequence>Sequence Number
ah sequence 123
ah sequence {23, 25, 33}
ah sequence != 23-33


esp match
spi <value>
esp spi 111
esp spi != 111-222
esp spi {111, 122 }
sequence <sequence>Sequence Number
esp sequence 123
esp sequence {23, 25, 33}
esp sequence != 23-33


comp match
nexthdr <protocol>Next header protocol (Upper layer protocol)
comp nexthdr != esp
comp nexthdr {esp, ah, comp, udp, udplite, tcp, tcp, dccp, sctp}
flags <flags>Flags
comp flags 0x0
comp flags != 0x33-0x45
comp flags {0x33, 0x55, 0x67, 0x88}
cpi <value>Compression Parameter Index
comp cpi 22
comp cpi != 33-45
comp cpi {33, 55, 67, 88}


icmp match
type <type>ICMP packet type
icmp type {echo-reply, destination-unreachable, source-quench, redirect, echo-request, time-exceeded, parameter-problem, timestamp-request, timestamp-reply, info-request, info-reply, address-mask-request, address-mask-reply, router-advertisement, router-solicitation}
codeICMP packet code
icmp code 111
icmp code != 33-55
icmp code { 2, 4, 54, 33, 56}
checksum <value>ICMP packet checksum
icmp checksum 12343
icmp checksum != 11-343
icmp checksum { 1111, 222, 343 }
id <value>ICMP packet id
icmp id 12343
icmp id != 11-343
icmp id { 1111, 222, 343 }
sequence <value>ICMP packet sequence
icmp sequence 12343
icmp sequence != 11-343
icmp sequence { 1111, 222, 343 }
mtu <value>ICMP packet mtu
icmp mtu 12343
icmp mtu != 11-343
icmp mtu { 1111, 222, 343 }
gateway <value>ICMP packet gateway
icmp gateway 12343
icmp gateway != 11-343
icmp gateway { 1111, 222, 343 }


icmpv6 match
type <type>ICMPv6 packet type
icmpv6 type {destination-unreachable, packet-too-big, time-exceeded, echo-request, echo-reply, mld-listener-query, mld-listener-report, mld-listener-reduction, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert, nd-redirect, parameter-problem, router-renumbering}
code <code>ICMPv6 packet code
icmpv6 code 4
icmpv6 code 3-66
icmpv6 code {5, 6, 7}
checksum <value>ICMPv6 packet checksum
icmpv6 checksum 12343
icmpv6 checksum != 11-343
icmpv6 checksum { 1111, 222, 343 }
id <value>ICMPv6 packet id
icmpv6 id 12343
icmpv6 id != 11-343
icmpv6 id { 1111, 222, 343 }
sequence <value>ICMPv6 packet sequence
icmpv6 sequence 12343
icmpv6 sequence != 11-343
icmpv6 sequence { 1111, 222, 343 }
mtu <value>ICMPv6 packet mtu
icmpv6 mtu 12343
icmpv6 mtu != 11-343
icmpv6 mtu { 1111, 222, 343 }
max-delay <value>ICMPv6 packet max delay
icmpv6 max-delay 33-45
icmpv6 max-delay != 33-45
icmpv6 max-delay {33, 55, 67, 88}


ether match
saddr <mac address>Source mac address
ether saddr 00:0f:54:0c:11:04
type <type>
ether type vlan


dst match
nexthdr <proto>Next protocol header
dst nexthdr { udplite, ipcomp, udp, ah, sctp, esp, dccp, tcp, ipv6-icmp}
dst nexthdr 22
dst nexthdr != 33-45
hdrlength <length>Header Length
dst hdrlength 22
dst hdrlength != 33-45
dst hdrlength { 33, 55, 67, 88 }


frag match
nexthdr <proto>Next protocol header
frag nexthdr { udplite, comp, udp, ah, sctp, esp, dccp, tcp, ipv6-icmp, icmp}
frag nexthdr 6
frag nexthdr != 50-51
reserved <value>
frag reserved 22
frag reserved != 33-45
frag reserved { 33, 55, 67, 88}
frag-off <value>
frag frag-off 22
frag frag-off != 33-45
frag frag-off { 33, 55, 67, 88}
more-fragments <value>
frag more-fragments 0
frag more-fragments 0
id <value>
frag id 1
frag id 33-45


hbh match
nexthdr <proto>Next protocol header
hbh nexthdr { udplite, comp, udp, ah, sctp, esp, dccp, tcp, icmpv6}
hbh nexthdr 22
hbh nexthdr != 33-45
hdrlength <length>Header Length
hbh hdrlength 22
hbh hdrlength != 33-45
hbh hdrlength { 33, 55, 67, 88 }


mh match
nexthdr <proto>Next protocol header
mh nexthdr { udplite, ipcomp, udp, ah, sctp, esp, dccp, tcp, ipv6-icmp }
mh nexthdr 22
mh nexthdr != 33-45
hdrlength <length>Header Length
mh hdrlength 22
mh hdrlength != 33-45
mh hdrlength { 33, 55, 67, 88 }
type <type>
mh type {binding-refresh-request, home-test-init, careof-test-init, home-test, careof-test, binding-update, binding-acknowledgement, binding-error, fast-binding-update, fast-binding-acknowledgement, fast-binding-advertisement, experimental-mobility-header, home-agent-switch-message}
mh type home-agent-switch-message
mh type != home-agent-switch-message
reserved <value>
mh reserved 22
mh reserved != 33-45
mh reserved { 33, 55, 67, 88}
checksum <value>
mh checksum 22
mh checksum != 33-45
mh checksum { 33, 55, 67, 88}


rt match
nexthdr <proto>Next protocol header
rt nexthdr { udplite, ipcomp, udp, ah, sctp, esp, dccp, tcp, ipv6-icmp }
rt nexthdr 22
rt nexthdr != 33-45
hdrlength <length>Header Length
rt hdrlength 22
rt hdrlength != 33-45
rt hdrlength { 33, 55, 67, 88 }
type <type>
rt type 22
rt type != 33-45
rt type { 33, 55, 67, 88 }
seg-left <value>
rt seg-left 22
rt seg-left != 33-45
rt seg-left { 33, 55, 67, 88}


vlan match
id <value>Vlan tag ID
vlan id 4094
vlan id 0
cfi <value>
vlan cfi 0
vlan cfi 1
pcp <value>
vlan pcp 7
vlan pcp 3


arp match
ptype <value>Payload type
arp ptype 0x0800
htype <value>Header type
arp htype 1
arp htype != 33-45
arp htype { 33, 55, 67, 88}
hlen <length>Header Length
arp hlen 1
arp hlen != 33-45
arp hlen { 33, 55, 67, 88}
plen <length>Payload length
arp plen 1
arp plen != 33-45
arp plen { 33, 55, 67, 88}
operation <value>
arp operation {nak, inreply, inrequest, rreply, rrequest, reply, request}


ct match
state <state>State of the connection
ct state { new, established, related, untracked }
ct state != related
ct state established
ct state 8
direction <value>Direction of the packet relative to the connection
ct direction original
ct direction != original
ct direction {reply, original}
status <status>Status of the connection
ct status expected
ct status != expected
ct status {expected,seen-reply,assured,confirmed,snat,dnat,dying}
mark [set]Mark of the connection
ct mark 0
ct mark or 0x23 == 0x11
ct mark or 0x3 != 0x1
ct mark and 0x23 == 0x11
ct mark and 0x3 != 0x1
ct mark xor 0x23 == 0x11
ct mark xor 0x3 != 0x1
ct mark 0x00000032
ct mark != 0x00000032
ct mark 0x00000032-0x00000045
ct mark != 0x00000032-0x00000045
ct mark {0x32, 0x2222, 0x42de3}
ct mark {0x32-0x2222, 0x4444-0x42de3}
ct mark set 0x11 xor 0x1331
ct mark set 0x11333 and 0x11
ct mark set 0x12 or 0x11
ct mark set 0x11
ct mark set mark
ct mark set mark map { 1 : 10, 2 : 20, 3 : 30 }
expirationConnection expiration time
ct expiration 30
ct expiration 30s
ct expiration != 233
ct expiration != 3m53s
ct expiration 33-45
ct expiration 33s-45s
ct expiration != 33-45
ct expiration != 33s-45s
ct expiration {33, 55, 67, 88}
ct expiration { 1m7s, 33s, 55s, 1m28s}
helper "<helper>"Helper associated with the connection
ct helper "ftp"
[original | reply] bytes <value>
ct original bytes > 100000
ct bytes > 100000
[original | reply] packets <value>
ct reply packets < 100
[original | reply] saddr <ip source address>
ct original saddr
ct reply saddr
ct original saddr
ct reply saddr
[original | reply] daddr <ip destination address>
ct original daddr
ct reply daddr
ct original daddr
ct reply daddr
[original | reply] l3proto <protocol>
ct original l3proto ipv4
[original | reply] protocol <protocol>
ct original protocol 6
[original | reply] proto-dst <port>
ct original proto-dst 22
[original | reply] proto-src <port>
ct reply proto-src 53


meta match
iifname <input interface name>Input interface name
meta iifname "eth0"
meta iifname != "eth0"
meta iifname {"eth0", "lo"}
meta iifname "eth*"
oifname <output interface name>Output interface name
meta oifname "eth0"
meta oifname != "eth0"
meta oifname {"eth0", "lo"}
meta oifname "eth*"
iif <input interface index>Input interface index
meta iif eth0
meta iif != eth0
oif <output interface index>Output interface index
meta oif lo
meta oif != lo
meta oif {eth0, lo}
iiftype <input interface type>Input interface type
meta iiftype {ether, ppp, ipip, ipip6, loopback, sit, ipgre}
meta iiftype != ether
meta iiftype ether
oiftype <output interface type>Output interface hardware type
meta oiftype {ether, ppp, ipip, ipip6, loopback, sit, ipgre}
meta oiftype != ether
meta oiftype ether
length <length>Length of the packet in bytes
meta length 1000
meta length != 1000
meta length > 1000
meta length 33-45
meta length != 33-45
meta length { 33, 55, 67, 88 }
meta length { 33-55, 67-88 }
protocol <protocol>ethertype protocol
meta protocol ip
meta protocol != ip
meta protocol { ip, arp, ip6, vlan }
nfproto <protocol>
meta nfproto ipv4
meta nfproto != ipv6
meta nfproto { ipv4, ipv6 }
l4proto <protocol>
meta l4proto 22
meta l4proto != 233
meta l4proto 33-45
meta l4proto { 33, 55, 67, 88 }
meta l4proto { 33-55 }
mark [set] <mark>Packet mark
meta mark 0x4
meta mark 0x00000032
meta mark and 0x03 == 0x01
meta mark and 0x03 != 0x01
meta mark != 0x10
meta mark or 0x03 == 0x01
meta mark or 0x03 != 0x01
meta mark xor 0x03 == 0x01
meta mark xor 0x03 != 0x01
meta mark set 0xffffffc8 xor 0x16
meta mark set 0x16 and 0x16
meta mark set 0xffffffe9 or 0x16
meta mark set 0xffffffde and 0x16
meta mark set 0x32 or 0xfffff
meta mark set 0xfffe xor 0x16
skuid <user id>UID associated with originating socket
meta skuid {bin, root, daemon}
meta skuid root
meta skuid != root
meta skuid lt 3000
meta skuid gt 3000
meta skuid eq 3000
meta skuid 3001-3005
meta skuid != 2001-2005
meta skuid { 2001-2005 }
skgid <group id>GID associated with originating socket
meta skgid {bin, root, daemon}
meta skgid root
meta skgid != root
meta skgid lt 3000
meta skgid gt 3000
meta skgid eq 3000
meta skgid 3001-3005
meta skgid != 2001-2005
meta skgid { 2001-2005 }
rtclassid <class>Routing realm
meta rtclassid cosmos
pkttype <type>Packet type
meta pkttype broadcast
meta pkttype != broadcast
meta pkttype { broadcast, unicast, multicast}
cpu <cpu index>CPU ID
meta cpu 1
meta cpu != 1
meta cpu 1-3
meta cpu != 1-2
meta cpu { 2,3 }
meta cpu { 2-3, 5-7 }
iifgroup <input group>Input interface group
meta iifgroup 0
meta iifgroup != 0
meta iifgroup default
meta iifgroup != default
meta iifgroup {default}
meta iifgroup { 11,33 }
meta iifgroup {11-33}
oifgroup <group>Output interface group
meta oifgroup 0
meta oifgroup != 0
meta oifgroup default
meta oifgroup != default
meta oifgroup {default}
meta oifgroup { 11,33 }
meta oifgroup {11-33}
cgroup <group>
meta cgroup 1048577
meta cgroup != 1048577
meta cgroup { 1048577, 1048578 }
meta cgroup 1048577-1048578
meta cgroup != 1048577-1048578
meta cgroup {1048577-1048578}


Statement, paket kuralla eşleştiğinde gerçekleştirilen eylemdir. Terminal ve terminal dışı olabilir. Belli bir kuralda, birkaç terminal dışı ifadeyi düşünebiliriz, yalnızca tek bir terminal bildirimi düşünebilirsiniz.
Statement, kural setindeki akış kontrolünü değiştirir ve paketler için politika kararları verir.
  • accept: Paketi kabul et ve kalıcı kurallar değerlendirmesini durdur.
  • drop: Paketi düşür ve kalan kuralların değerlendirmesini durdurun.
  • queue: Paketi kuyruğa al ve kalan kural değerlendirmesini durdurun.
  • continue: Bir sonraki kuralla kural seti değerlendirmesine devam edin.
  • return: Geçerli zincirden dönün ve son zincirin bir sonraki kuralı ile devam edin. Base zincirinde accept ile eş değerdir.
  • jump <chain>: <chain> ile belirtilen zincirin ilk kuralıyla devam edin. İade ifadesinin yayınlanmasının ardından bir sonraki kuralda devam edecektir.
  • goto <chain>: Jump'a benzer, ancak yeni zincirden sonra değerlendirme, goto deyimini içeren son zincirde devam edecektir.
log statement
level [over] <value> <unit> [burst <value> <unit>]Log level
log level emerg
log level alert
log level crit
log level err
log level warn
log level notice
log level info
log level debug
group <value> [queue-threshold <value>] [snaplen <value>] [prefix "<prefix>"]
log prefix aaaaa-aaaaaa group 2 snaplen 33
log group 2 queue-threshold 2
log group 2 snaplen 33

reject statement
with <protocol> type <type>
reject with icmp type host-unreachable
reject with icmp type net-unreachable
reject with icmp type prot-unreachable
reject with icmp type port-unreachable
reject with icmp type net-prohibited
reject with icmp type host-prohibited
reject with icmp type admin-prohibited
reject with icmpv6 type no-route
reject with icmpv6 type admin-prohibited
reject with icmpv6 type addr-unreachable
reject with icmpv6 type port-unreachable
ip protocol tcp reject with tcp reset
reject with icmpx type host-unreachable
reject with icmpx type no-route
reject with icmpx type admin-prohibited
reject with icmpx type port-unreachable

counter statement
packets <packets> bytes <bytes>
counter packets 0 bytes 0

limit statement
rate [over] <value> <unit> [burst <value> <unit>]Rate limit
limit rate 400/minute
limit rate 400/hour
limit rate over 40/day
limit rate over 400/week
limit rate over 1023/second burst 10 packets
limit rate 1025 kbytes/second
limit rate 1023000 mbytes/second
limit rate 1025 bytes/second burst 512 bytes
limit rate 1025 kbytes/second burst 1023 kbytes
limit rate 1025 mbytes/second burst 1025 kbytes
limit rate 1025000 mbytes/second burst 1023 mbytes
nat statement
dnat <destination address>Destination address translation
dnat ct mark map { 0x00000014 :}
snat <ip source address>Source address translation
snat 2001:838:35f:1::-2001:838:35f:2:::100
masquerade [<type>] [to :<port>]Masquerade
masquerade persistent,fully-random,random
masquerade to :1024
masquerade to :1024-2048
queue statement
num <value> <scheduler>
queue num 2
queue num 2-3
queue num 4-5 fanout bypass
queue num 4-5 fanout
queue num 4-5 bypass

Olayları İzleme
  • nft monitor [new | destroy]  [tables | chains | sets | rules | elements]  [xml | json]
komutu ile filtreleme olaylarını izleyebilirsiniz.

Basit IP / IPv6 Güvenlik Duvarı Örneği

flush ruleset

table firewall {
  chain incoming {
    type filter hook input priority 0; policy drop;

    # established/related connections
    ct state established,related accept

    # loopback interface
    iifname lo accept

    # icmp
    icmp type echo-request accept

    # open tcp ports: sshd (22), httpd (80)
    tcp dport {ssh, http} accept

table ip6 firewall {
  chain incoming {
    type filter hook input priority 0; policy drop;

    # established/related connections
    ct state established,related accept

    # invalid connections
    ct state invalid drop

    # loopback interface
    iifname lo accept

    # icmp
    # routers may also want: mld-listener-query, nd-router-solicit
    icmpv6 type {echo-request,nd-neighbor-solicit} accept

    # open tcp ports: sshd (22), httpd (80)
    tcp dport {ssh, http} accept