Linux Networking & TCP/IP for Developers · 강의

고급 방화벽 규칙(nftables)

`iptables`를 넘어 `nftables`를 사용하여 더 유연하고 강력한 패킷 필터링과 네트워크 주소 변환을 구현합니다.

레슨 1/411개 단계

고급 방화벽 규칙(nftables)은(는) CoddyKit의 무료 Linux Networking & TCP/IP for Developers 강의입니다. 이것은 4개 중 1번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Linux Networking & TCP/IP for Developers 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Linux Networking & TCP/IP for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

Meet nftables: The Modern Firewall

Welcome to nftables, the modern packet filtering framework for Linux! It's designed to be more flexible and easier to use than its predecessor, iptables.

While iptables uses separate tools for IPv4, IPv6, and bridging, nftables provides a unified syntax. This means you can manage all your firewall rules with a single command-line utility: nft.

Organizing with Families, Tables, Chains

nftables organizes rules into a clear hierarchy:

  • Families: Define the network layer (e.g., ip for IPv4, ip6 for IPv6, bridge for Layer 2, netdev for Layer 1/2).
  • Tables: Containers for chains, belonging to a specific family. You can have multiple tables.
  • Chains: Sequences of rules that packets are evaluated against. Chains can be "base chains" (entry points for kernel hooks) or "regular chains" (called by other chains).

Listing Existing nftables Rules

To see the current nftables ruleset on your system, you use the nft list ruleset command. If you're just starting, it might be empty or contain default rules.

Let's take a look:

nft list ruleset

Setting Up Your First Firewall

Before adding rules, we need a table and a chain. A common practice is to create a table for the ip family (IPv4) and a base chain named input for incoming traffic.

We'll set the default policy for this chain to drop, meaning any packet not explicitly allowed will be discarded. This is a secure "deny by default" approach.

#!/bin/bash
# Add an 'ip' family table named 'filter'
nft add table ip filter

# Add a base chain 'input' to the 'filter' table
# Type 'filter', hook 'input', priority 0, policy 'drop'
nft add chain ip filter input { type filter hook input priority 0 \; policy drop \; }

nft list ruleset

Allowing Basic Inbound Traffic

Now that our input chain drops everything by default, we need to add rules to allow necessary traffic. A common first step is to permit inbound SSH connections (port 22) so you can manage your server remotely.

We'll also allow established and related connections to ensure ongoing communication works, which is crucial for most network interactions.

#!/bin/bash
# Allow established and related connections
nft add rule ip filter input ct state established,related accept

# Allow inbound SSH traffic (TCP port 22)
nft add rule ip filter input tcp dport 22 accept

nft list ruleset

Enabling Outgoing Connections

Most systems need to initiate outbound connections (e.g., to fetch updates, browse the web). We typically create an output base chain.

For simplicity, let's create an output chain and allow all outgoing IPv4 traffic. In production, you might restrict this more tightly.

#!/bin/bash
# Add a base chain 'output' to the 'filter' table
# Type 'filter', hook 'output', priority 0, policy 'accept'
nft add chain ip filter output { type filter hook output priority 0 \; policy accept \; }

nft list ruleset

Source NAT (SNAT) with nftables

Network Address Translation (NAT) allows multiple devices on a private network to share a single public IP address. Source NAT (SNAT) changes the source IP of outgoing packets.

This is commonly used on routers to allow internal clients to access the internet. Here, we set up a basic SNAT rule for traffic going out through eth0, masquerading it with the public IP of eth0.

#!/bin/bash
# Add an 'ip' family table named 'nat'
nft add table ip nat

# Add a base chain 'postrouting' to the 'nat' table
# Type 'nat', hook 'postrouting', priority 100
nft add chain ip nat postrouting { type nat hook postrouting priority 100 \; }

# Add a rule to masquerade (SNAT) traffic leaving 'eth0'
nft add rule ip nat postrouting oifname "eth0" masquerade

nft list ruleset

Destination NAT (DNAT) with nftables

Destination NAT (DNAT), also known as port forwarding, changes the destination IP address and/or port of incoming packets. This allows external users to access services on an internal server.

For example, you might forward external port 80 to an internal web server at 192.168.1.5 on port 80. This rule would be placed in the prerouting chain.

#!/bin/bash
# Add a base chain 'prerouting' to the 'nat' table
# Type 'nat', hook 'prerouting', priority -100
nft add chain ip nat prerouting { type nat hook prerouting priority -100 \; }

# Forward external TCP port 80 to internal server 192.168.1.5:80
nft add rule ip nat prerouting tcp dport 80 dnat to 192.168.1.5:80

nft list ruleset

Saving Your Firewall Configuration

Rules added with nft directly on the command line are temporary and will be lost after a reboot. To make them permanent, you need to save them to a configuration file.

The standard way is to save the current ruleset to /etc/nftables.conf and ensure the nftables service is enabled to load it on boot. You can then restore them with nft -f /etc/nftables.conf.

#!/bin/bash
# Save the current ruleset to the default configuration file
nft list ruleset > /etc/nftables.conf

echo "Configuration saved to /etc/nftables.conf"
# On a real system, you'd typically also enable the service:
# sudo systemctl enable nftables
# sudo systemctl start nftables

Test Your nftables Knowledge

You've learned about nftables structure and basic rules. Let's test your understanding.

nftables: Modern Firewalling

Great job! You've taken your first steps with nftables, the powerful and flexible successor to iptables.

  • You learned about its unified structure using families, tables, and chains.
  • You practiced adding basic filter rules for inbound and outbound traffic.
  • You explored configuring Source NAT (SNAT) and Destination NAT (DNAT).
  • Finally, you understood how to save your rules for persistence across reboots.

Keep experimenting with nftables to secure and manage your Linux network!

무료로 시작

AI 튜터와 함께 Linux Networking & TCP/IP for Developers을(를) 배우세요 — 무료

브라우저에서 실제 코드를 작성하고 실행하며, 24/7 AI 튜터로부터 즉각적인 도움을 받고, 웹이나 앱에서 중단한 부분부터 계속 학습하세요.

코스
12
레슨
48

자주 묻는 질문

“고급 방화벽 규칙(nftables)” 강의는 무료인가요?

네 — “고급 방화벽 규칙(nftables)” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Linux Networking & TCP/IP for Developers 강의 전체를 잠금 해제할 수 있습니다. Linux Networking & TCP/IP for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.

“고급 방화벽 규칙(nftables)”에서 뭘 배우나요?

`iptables`를 넘어 `nftables`를 사용하여 더 유연하고 강력한 패킷 필터링과 네트워크 주소 변환을 구현합니다. 브라우저에서 직접 실행하는 실습 코드로 Linux Networking & TCP/IP for Developers을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Linux Networking & TCP/IP for Developers을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Linux Networking & TCP/IP for Developers은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 1번째 강의입니다.

“고급 방화벽 규칙(nftables)” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Linux Networking & TCP/IP for Developers 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Linux Networking & TCP/IP for Developers 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. 고급 방화벽 규칙(nftables)
  2. VPN 개념 및 구성
  3. 네트워크 침입 탐지(IDS)
  4. SSH 강화 및 키 기반 인증
← Linux Networking & TCP/IP for Developers(으)로 돌아가기