firewalld and nftables

firewalld and nftables on Red Hat Systems

Fedora 1,480 , RHEL 664 , Rocky and AlmaLinux 7,122 ship firewalld 292,900 enabled, with nftables 40,292 as its backend (upstream is at 2.5.2, released 17 September 2026). It differs from ufw 280 twice over. Interfaces belong to zones, and the default zone, public, admits only a few services such as SSH. And each change is either runtime (live now, gone at the next reload) or permanent (saved in /etc/firewalld/, live after a reload). No RHEL system was available for this book's runs, so these commands appear without output:

Opening HTTP and HTTPS with firewalldShell
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

http and https are definitions in /usr/lib/firewalld/services/ for 80/tcp and 443/tcp, and --add-port=8080/tcp opens a bare port. Forget --permanent and the port opens, the test passes, and the next reboot closes it; --runtime-to-permanent saves what you tested live.

Beneath both tools sits nftables: with ufw active, sudo nft list chain ip filter ufw-user-input showed tcp dport 80 counter packets 1 bytes 52 accept. For full control, or one policy for every distribution, write nftables directly:

web.nft: a web server's inbound policy in native nftablesShell
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
  chain input {
    type filter hook input priority filter; policy drop;
    ct state established,related accept
    ct state invalid drop
    iif "lo" accept
    meta l4proto { icmp, ipv6-icmp } accept
    tcp dport { 80, 443 } accept
    ip saddr 198.51.100.7 tcp dport 22 accept
    counter comment "dropped by policy"
  }
  chain forward { type filter hook forward priority filter; policy drop; }
}

The inet family covers IPv4 and IPv6 at once, and ct state established,related accept makes the policy stateful: replies to connections the server opened need no rule. sudo nft -c -f web.nft checks the syntax and sudo nft -f web.nft loads it. Loaded into an isolated network namespace here and probed from outside, port 80 answered HTTP 200, port 8086 timed out, and the last rule counted 3 dropped packets. The nftables service loads /etc/nftables.conf on Ubuntu 225 and /etc/sysconfig/nftables.conf on RHEL. Run one manager only: flush ruleset deletes every table, firewalld's included.