#nftables
One of the most useful findings: a broad nftables established-connection rule let a known TCP flow emit a FIN over the physical interface during reboot. Removing it stopped the reproduced escape.

GitHub: github.com/Fragmented-S...
GitHub - Fragmented-Sentinel/what-a-vpn-actually-hides: Independent technical verification of AirVPN over WireGuard: DNS privacy, IPv4/IPv6 routing, kill-switch behaviour, bypass testing, and trust bo...
Independent technical verification of AirVPN over WireGuard: DNS privacy, IPv4/IPv6 routing, kill-switch behaviour, bypass testing, and trust boundaries. - Fragmented-Sentinel/what-a-vpn-actually-h...
github.com
September 29, 2026 at 1:41 AM
Все що знаю з альтернатив sudo то це doas ну й юзаю nftables до речі бо колись сказали що він в чомусь кращий :yellow_nerd:
September 27, 2026 at 5:52 PM
The biggest surprise: my kill switch looked configured, but it was broken.
nftables had failed at boot because it referenced the VPN interface before it existed. When WireGuard stopped, the VM quietly fell back to normal Internet access.
That was the best lesson in the whole project.
September 27, 2026 at 5:52 AM
took a lil bit of trial and error with nftables to make it work properly after a reboot...
September 26, 2026 at 5:11 PM
TransparentTorProxy — A Linux CLI utility that transparently routes all system traffic through the Tor network using nftables. It enables rapid IP rotation and easy toggling of global proxy settings for privacy tasks. https://ktp.sh/lLYbtWIzFj
September 23, 2026 at 2:59 PM
WireGuard, tu túnel privado a casa

Hasta ahora has cerrado puertas. En el capítulo 1 blindaste SSH con llaves Ed25519 y un puerto personalizado. En el capítulo 2 montaste nftables con.....

https://atareao.es/tutorial/seguridad-esencial-en-self-hosted/wireguard-tu-tunel-privado-a-casa/
September 22, 2026 at 8:05 AM
My coworkers are discussing nftables versus iptables versus firewalld. I'm like "what about awall?" Cue all the "what the fuck is awall" from the Docker boys who never realized that there's an OS underneath their YAML files.
September 21, 2026 at 6:39 PM
Cosinium is releasing beta images for trial setups. Free licenses will be given to students. Trial period will let you test all the features - Cosinium firewall, Cosineq post-quantum mesh-VPN. See cosinium.com for what they are, and why we're different.

#firewalls #nftables #post-quantum #meshvpn
September 18, 2026 at 2:35 AM
Goodbye iptables, hello nftables!

Ubuntu 24.04 and Debian 12 have already phased out iptables under the hood. Learn how to safely migrate your Linux firewall to native nftables syntax to unify IPv4/IPv6 and boost performance.

Read our step-by-step guide:
www.eservers.uk/tutorials/ho...
September 17, 2026 at 5:40 AM
This walk through covers configuring nftables on the Debian firewall. #CybersecurityLab #nftables #Firewalls

Building a cybersecurity virtual lab 3/7: Configuring nftables on the Debian firewall
drive.proton.me/urls/6CWHJ02...
September 16, 2026 at 8:08 PM
Nginx 429 logs + Fail2ban = kernel-level IP bans. Parse rate limit hits, escalate repeat offenders to iptables/nftables automatically. Ubuntu, Debian, https://www.valtersit.com/vault/automated-ip-firewall-escalation-for-repeated-nginx-rate-lim-6851e6/
#fail2ban #nginx #iptables
September 15, 2026 at 2:20 AM
i always read nftables as nice fuckin' tables
September 13, 2026 at 11:43 PM
Banning IPs via classic firewall tools (iptables/nftables/etc.) still works great for banning an annoying IP (or even subnet ranges, when they change in the same data center etc.)

A bit cat and mouse, but automations like Ansible exist.

Maybe there should be a DNS based IP blacklist like for SMTP?
September 13, 2026 at 1:02 PM
これ、fail2banで設定してもBANの実装はデフォルトだとiptables/firewalld/nftablesで行われるので、手順0に記載されている「Cloudflare・ロードバランサ・リバースプロキシの配下」の場合は結局効かないと思います。
アクセスログから不正アクセスの兆候を見つける7つの集計(nginx/Apache対応・コピペOK) - Qiita
「うちのサイト、攻撃されていませんか?」と聞かれたとき、答えはたいていサーバのアクセスログの中にあります。ただ生ログを tail で眺めても、1 日数万行の中から異常だけを拾うことはできません。 この記事は、サーバに SSH で入れる Web 担当者・サイト運営者・制作会社...
qiita.com
September 13, 2026 at 9:18 AM
Finally got fed up with the limitations of my consumer-grade DSL router. Flipped it into bridging mode and now my pi4 server does all of my routing and firewalling. So much more flexible!

Though, I made the firewall rules using iptables. I guess I really should learn nftables. And even though I […]
Original post on mastodon.social
mastodon.social
September 9, 2026 at 9:47 PM
can I use it if I did it w nftables once
September 7, 2026 at 8:15 AM
Turned on nftables flowtables and forwarding soared. Then

#Linux #Networking #Nftables #Kernel

https://mustafaerbay.com.tr/en/blog/tutorials/nftables-flowtable-hizin-bedeli-gorunurluk/
nftables flowtable: Speed Paid for in Visibility
Flowtable routes established flows around the firewall and speeds forwarding up. The gain is real — but your rules after ingress no longer see those packets.
mustafaerbay.com.tr
September 6, 2026 at 8:57 AM
Savaş alanında hızlı bir adım: flowtable akışları duvarın etrafından süzerek hızlandırıyor. Ama düşmanım, girişin ardından kurallarım artık onları göremiyor. H…

#Linux #Networking #Nftables #Kernel

https://mustafaerbay.com.tr/blog/tutorials/nftables-flowtable-hizin-bedeli-gorunurluk/
nftables flowtable: Hızın Bedeli Görünürlük
Flowtable, kurulmuş akışları güvenlik duvarının etrafından dolaştırıp yönlendirmeyi hızlandırıyor. Kazanç gerçek; ama ingress'ten sonraki kurallarınız o paketleri artık görmüyor.
mustafaerbay.com.tr
September 6, 2026 at 8:56 AM
also please if anyone knows anything that lets me list out nftables data that ISN'T the nft CLI / is faster I beg you to tell me lmfao it takes ages to process
September 3, 2026 at 6:53 AM