nftables

Наследник iptables в netfilter. Единый инструмент вместо zoo из iptables/ip6tables/arptables/ebtables.

Отличия

Пример

nft add table inet filter
nft add chain inet filter input { type filter hook input priority 0 \; policy drop \; }
nft add rule inet filter input tcp dport 22 accept

Многие пишут правила через firewalld / ufw / OPNsense — те под капотом уже nft.