Linux

Where Is the nftables Config File on Linux?

nftables loads firewall rulesets from /etc/nftables.conf on most Linux distributions.

Last updated

nftables centers on /etc/nftables.conf with include files for tables, chains, and sets. The systemd unit loads it at boot, replacing legacy iptables restores on modern distros.

Back up the conf plus includes before filter experiments. Check syntax with the check flag before flushing live rules. A bad reload can lock out remote hosts, so keep a console path open.

Where nftables stores this, by platform

Linux
/etc/nftables.conf

Ruleset plus includes. Root owned. Validate with nft check before applying. Some distros use /etc/sysconfig instead.

Frequently asked questions

How do I back up nftables rules?

Save the live ruleset with list ruleset plus the conf files. Restore files first, then load them. Test from console to avoid lockouts.

nftables or iptables files, which is live?

nftables on current distros with the conf above. Legacy iptables-save files linger unused. Confirm with the active systemd unit.

Notice an outdated path? Let us know.