Die Linux-Firewall mit nftables konfigurieren
Steuern Sie eingehenden und ausgehenden Traffic auf einem Linux-Host mit nftables und dem benutzerfreundlichen ufw-Frontend, um Ihre Netzwerkdienste abzusichern.
Die Linux-Firewall mit nftables konfigurieren ist eine kostenlose Linux Networking & TCP/IP for Developers-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Linux Networking & TCP/IP for Developers-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Linux Networking & TCP/IP for Developers-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
Why a Host Firewall?
A host firewall decides which packets are allowed in or out of a single machine. It is your last line of defense, protecting services even when the network perimeter is breached.
From iptables to nftables
Modern Linux uses nftables as the kernel packet-filtering framework, replacing the older iptables. It uses tables, chains, and rules but with a cleaner, unified syntax.
Tables, Chains, and Rules
In nftables a table holds chains, a chain holds ordered rules, and each rule matches packets and takes an action like accept or drop. Chains hook into traffic at points such as input and output.
Listing the Ruleset
See the entire active configuration with a single command. This is always your first step before changing anything.
sudo nft list rulesetA Simple Input Policy
Create a table and an input chain with a default drop policy, then allow only what you need. Default-deny is the secure baseline.
sudo nft add table inet filter
sudo nft add chain inet filter input { type filter hook input priority 0 \; policy drop \; }Allowing SSH
Add a rule to accept incoming TCP on port 22 so you do not lock yourself out before allowing anything else.
sudo nft add rule inet filter input tcp dport 22 acceptAllowing Established Traffic
Permit replies to connections you initiated by accepting established and related traffic. Without this, outbound requests get no responses.
sudo nft add rule inet filter input ct state established,related acceptThe Easier Way: ufw
For everyday use, ufw (Uncomplicated Firewall) is a friendly front-end. It manages the underlying rules with simple commands.
sudo ufw allow 22/tcp
sudo ufw enableChecking ufw Status
Verify which rules ufw has applied and whether it is active.
sudo ufw status verbosePersisting Rules
nftables rules added at the command line vanish on reboot. Save them to /etc/nftables.conf and enable the service so they reload automatically.
sudo nft list ruleset | sudo tee /etc/nftables.conf
sudo systemctl enable nftablesLogging Dropped Packets
Add a logging rule before the final drop so you can see what is being blocked. This is invaluable when a service mysteriously cannot be reached.
sudo nft add rule inet filter input log prefix "dropped: "Quick Check
Test your firewall knowledge.
Recap
You learned to configure the Linux firewall.
- nftables uses tables, chains, and rules with a default-deny baseline.
- Always allow SSH and established traffic before locking down.
- ufw simplifies common rules; persist nftables to survive reboots.
Häufig gestellte Fragen
Ist die Lektion „Die Linux-Firewall mit nftables konfigurieren“ kostenlos?
Ja — der vollständige Text von „Die Linux-Firewall mit nftables konfigurieren“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Linux Networking & TCP/IP for Developers-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Linux Networking & TCP/IP for Developers-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Die Linux-Firewall mit nftables konfigurieren“?
Steuern Sie eingehenden und ausgehenden Traffic auf einem Linux-Host mit nftables und dem benutzerfreundlichen ufw-Frontend, um Ihre Netzwerkdienste abzusichern. Du übst Linux Networking & TCP/IP for Developers mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Linux Networking & TCP/IP for Developers zu starten?
Keine Vorkenntnisse erforderlich. Linux Networking & TCP/IP for Developers auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.
Wie lange dauert die Lektion „Die Linux-Firewall mit nftables konfigurieren“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Linux Networking & TCP/IP for Developers-Lektion Code schreiben und ausführen?
Ja. Jede Linux Networking & TCP/IP for Developers-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Netzwerkschnittstellen verwalten
- Routingtabellen und Gateways
- DNS-Konfiguration und Namensauflösung
- Die Linux-Firewall mit nftables konfigurieren