Difference between revisions of "Nftables"

From ArchWiki
Jump to: navigation, search
(Usage)
Line 16: Line 16:
 
  # nft add rule ip filter output ip daddr 1.2.3.4 drop
 
  # nft add rule ip filter output ip daddr 1.2.3.4 drop
  
 +
Drop packet to port 80:
 +
 +
# nft add rule ip filter input tcp dport 80 drop
  
 
==Further reading==
 
==Further reading==

Revision as of 17:11, 20 January 2014

Related articles

nftables is the candidate for replacing iptables as the main Linux firewall utility from Linux kernel version 3.13 and on.

Currently, nftables is available on the AUR in package nftables-gitAUR.

Usage

Drop output to a destination:

# nft add rule ip filter output ip daddr 1.2.3.4 drop

Drop packet to port 80:

# nft add rule ip filter input tcp dport 80 drop

Further reading