Расширенные правила брандмауэра (nftables)
Перейдите от `iptables` к `nftables` для более гибкой и мощной фильтрации пакетов и трансляции сетевых адресов
«Расширенные правила брандмауэра (nftables)» — бесплатный урок Linux Networking & TCP/IP for Developers на CoddyKit. Это урок 1 из 4. Ты можешь прочитать весь урок бесплатно ниже — а потом практиковать его прямо в браузере с встроенным редактором кода и ИИ-репетитором 24/7. Это часть пути обучения Linux Networking & TCP/IP for Developers, и твой прогресс синхронизируется между веб-версией и приложением CoddyKit. Курс Linux Networking & TCP/IP for Developers содержит 4 уроков всего.
Части этого урока еще не переведены и отображаются на английском.
Meet nftables: The Modern Firewall
Welcome to nftables, the modern packet filtering framework for Linux! It's designed to be more flexible and easier to use than its predecessor, iptables.
While iptables uses separate tools for IPv4, IPv6, and bridging, nftables provides a unified syntax. This means you can manage all your firewall rules with a single command-line utility: nft.
Organizing with Families, Tables, Chains
nftables organizes rules into a clear hierarchy:
- Families: Define the network layer (e.g.,
ipfor IPv4,ip6for IPv6,bridgefor Layer 2,netdevfor Layer 1/2). - Tables: Containers for chains, belonging to a specific family. You can have multiple tables.
- Chains: Sequences of rules that packets are evaluated against. Chains can be "base chains" (entry points for kernel hooks) or "regular chains" (called by other chains).
Listing Existing nftables Rules
To see the current nftables ruleset on your system, you use the nft list ruleset command. If you're just starting, it might be empty or contain default rules.
Let's take a look:
nft list rulesetSetting Up Your First Firewall
Before adding rules, we need a table and a chain. A common practice is to create a table for the ip family (IPv4) and a base chain named input for incoming traffic.
We'll set the default policy for this chain to drop, meaning any packet not explicitly allowed will be discarded. This is a secure "deny by default" approach.
#!/bin/bash
# Add an 'ip' family table named 'filter'
nft add table ip filter
# Add a base chain 'input' to the 'filter' table
# Type 'filter', hook 'input', priority 0, policy 'drop'
nft add chain ip filter input { type filter hook input priority 0 \; policy drop \; }
nft list rulesetAllowing Basic Inbound Traffic
Now that our input chain drops everything by default, we need to add rules to allow necessary traffic. A common first step is to permit inbound SSH connections (port 22) so you can manage your server remotely.
We'll also allow established and related connections to ensure ongoing communication works, which is crucial for most network interactions.
#!/bin/bash
# Allow established and related connections
nft add rule ip filter input ct state established,related accept
# Allow inbound SSH traffic (TCP port 22)
nft add rule ip filter input tcp dport 22 accept
nft list rulesetEnabling Outgoing Connections
Most systems need to initiate outbound connections (e.g., to fetch updates, browse the web). We typically create an output base chain.
For simplicity, let's create an output chain and allow all outgoing IPv4 traffic. In production, you might restrict this more tightly.
#!/bin/bash
# Add a base chain 'output' to the 'filter' table
# Type 'filter', hook 'output', priority 0, policy 'accept'
nft add chain ip filter output { type filter hook output priority 0 \; policy accept \; }
nft list rulesetSource NAT (SNAT) with nftables
Network Address Translation (NAT) allows multiple devices on a private network to share a single public IP address. Source NAT (SNAT) changes the source IP of outgoing packets.
This is commonly used on routers to allow internal clients to access the internet. Here, we set up a basic SNAT rule for traffic going out through eth0, masquerading it with the public IP of eth0.
#!/bin/bash
# Add an 'ip' family table named 'nat'
nft add table ip nat
# Add a base chain 'postrouting' to the 'nat' table
# Type 'nat', hook 'postrouting', priority 100
nft add chain ip nat postrouting { type nat hook postrouting priority 100 \; }
# Add a rule to masquerade (SNAT) traffic leaving 'eth0'
nft add rule ip nat postrouting oifname "eth0" masquerade
nft list rulesetDestination NAT (DNAT) with nftables
Destination NAT (DNAT), also known as port forwarding, changes the destination IP address and/or port of incoming packets. This allows external users to access services on an internal server.
For example, you might forward external port 80 to an internal web server at 192.168.1.5 on port 80. This rule would be placed in the prerouting chain.
#!/bin/bash
# Add a base chain 'prerouting' to the 'nat' table
# Type 'nat', hook 'prerouting', priority -100
nft add chain ip nat prerouting { type nat hook prerouting priority -100 \; }
# Forward external TCP port 80 to internal server 192.168.1.5:80
nft add rule ip nat prerouting tcp dport 80 dnat to 192.168.1.5:80
nft list rulesetSaving Your Firewall Configuration
Rules added with nft directly on the command line are temporary and will be lost after a reboot. To make them permanent, you need to save them to a configuration file.
The standard way is to save the current ruleset to /etc/nftables.conf and ensure the nftables service is enabled to load it on boot. You can then restore them with nft -f /etc/nftables.conf.
#!/bin/bash
# Save the current ruleset to the default configuration file
nft list ruleset > /etc/nftables.conf
echo "Configuration saved to /etc/nftables.conf"
# On a real system, you'd typically also enable the service:
# sudo systemctl enable nftables
# sudo systemctl start nftablesTest Your nftables Knowledge
You've learned about nftables structure and basic rules. Let's test your understanding.
nftables: Modern Firewalling
Great job! You've taken your first steps with nftables, the powerful and flexible successor to iptables.
- You learned about its unified structure using families, tables, and chains.
- You practiced adding basic filter rules for inbound and outbound traffic.
- You explored configuring Source NAT (SNAT) and Destination NAT (DNAT).
- Finally, you understood how to save your rules for persistence across reboots.
Keep experimenting with nftables to secure and manage your Linux network!
Часто задаваемые вопросы
Урок «Расширенные правила брандмауэра (nftables)» бесплатный?
Да — полный текст урока «Расширенные правила брандмауэра (nftables)» бесплатно доступен здесь в веб-версии. Чтобы практиковать его интерактивно (встроенный редактор кода и ИИ-репетитор 24/7) и разблокировать остальной курс Linux Networking & TCP/IP for Developers, подпишись на CoddyKit PRO. Курс Linux Networking & TCP/IP for Developers содержит 4 уроков всего.
Чему я научусь в уроке «Расширенные правила брандмауэра (nftables)»?
Перейдите от `iptables` к `nftables` для более гибкой и мощной фильтрации пакетов и трансляции сетевых адресов Ты практикуешь Linux Networking & TCP/IP for Developers с помощью реального кода, который запускаешь прямо в браузере, и ИИ-репетитор 24/7 отвечает на твои вопросы во время урока.
Нужен ли мне опыт, чтобы начать Linux Networking & TCP/IP for Developers?
Предыдущий опыт не требуется. Linux Networking & TCP/IP for Developers на CoddyKit структурирован для всех уровней — от новичков до продвинутых, поэтому ты можешь начать отсюда или с самого начала и учиться в своем темпе. Это урок 1 из 4.
Сколько времени занимает урок «Расширенные правила брандмауэра (nftables)»?
Большинство уроков CoddyKit занимают около 5–10 минут. Каждый из них компактный и интерактивный, поэтому ты постоянно делаешь прогресс и продолжаешь с того же места в веб-версии и приложении.
Можно ли писать и запускать код в этом уроке Linux Networking & TCP/IP for Developers?
Да. Каждый урок Linux Networking & TCP/IP for Developers включает встроенный редактор кода, поэтому ты пишешь и запускаешь реальный код прямо в браузере и получаешь моментальную обратную связь от AI — локальная установка не требуется.
Все уроки этого курса
- Расширенные правила брандмауэра (nftables)
- Понятия и настройка VPN
- Обнаружение вторжений в сеть (IDS)
- Усиление защиты SSH и аутентификация по ключу