Guía

Un firewall nftables correcto, incluyendo IPv6

Intermedio15 min de lecturaActualizado 22 de abril de 2026
Respuesta corta

nftables reemplaza iptables con un solo conjunto de reglas unificado que cubre IPv4 e IPv6 juntos mediante la familia inet. Una política base correcta bloquea entrantes por defecto, acepta conexiones establecidas, permite loopback e ICMP, y abre solo los puertos que sirves.

01 Por qué importa la familia inet

The most common firewall mistake on a modern VPS is a v4-only ruleset. Every OnionVPS instance has a routed IPv6 /64, so services remain fully reachable over v6 unless the ruleset covers both. The inet family covers both in one place.

02 Un conjunto base completo de reglas

Write it to /etc/nftables.conf and enable the service. Keep a second session open while testing.

#!/usr/sbin/nft -f
flush ruleset

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;

    ct state established,related accept
    ct state invalid drop
    iif lo accept

    ip protocol icmp accept
    ip6 nexthdr icmpv6 accept

    tcp dport { 22, 80, 443 } accept
    udp dport 51820 accept          # WireGuard

    limit rate 5/minute burst 10 packets log prefix "nft-drop: "
  }
  chain forward { type filter hook forward priority 0; policy drop; }
  chain output  { type filter hook output  priority 0; policy accept; }
}

03 Aplícalo de forma segura

Schedule a flush before applying, so a mistake resolves itself rather than requiring the console.

echo 'nft flush ruleset' | at now + 10 minutes
nft -f /etc/nftables.conf
# verify you are still connected, then:
atrm $(atq | cut -f1)
systemctl enable nftables

04 Nunca bloquees ICMPv6

IPv6 depends on ICMPv6 for neighbour discovery and path MTU discovery. Blocking it wholesale, which people do out of IPv4 habit, produces intermittent failures that are extremely hard to diagnose.

Preguntas frecuentes

¿Debería usar nftables o ufw?

ufw es un frontend más amigable y maneja ambas familias de direcciones correctamente por defecto. Usa nftables directamente cuando necesites reglas que ufw no puede expresar, como limitación de velocidad o NAT.

¿Cómo veo lo que se está descartando?

La regla de registro anterior escribe en el registro del kernel con un prefijo "nft-drop"; léelo con journalctl -k -g nft-drop.