Rehber

IPv6 dahil doğru bir nftables güvenlik duvarı

Orta seviye15 dk okumaGüncellendi 22 Nisan 2026
Kısa cevap

nftables, iptables'ın yerini inet ailesi aracılığıyla IPv4 ve IPv6'yı birlikte kapsayan tek bir birleşik kural kümesiyle alır. Doğru bir temel politika, varsayılan olarak gelen trafiği reddeder, kurulmuş bağlantıları kabul eder, loopback ve ICMP'ye izin verir ve yalnızca sunduğunuz bağlantı noktalarını açar.

01 inet ailesi neden önemlidir

The most common firewall mistake on a modern VPS is a v4-only ruleset. Every OnionVPS instance has a routed IPv6 /64, so services remain fully reachable over v6 unless the ruleset covers both. The inet family covers both in one place.

02 Eksiksiz bir temel kural kümesi

Write it to /etc/nftables.conf and enable the service. Keep a second session open while testing.

#!/usr/sbin/nft -f
flush ruleset

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;

    ct state established,related accept
    ct state invalid drop
    iif lo accept

    ip protocol icmp accept
    ip6 nexthdr icmpv6 accept

    tcp dport { 22, 80, 443 } accept
    udp dport 51820 accept          # WireGuard

    limit rate 5/minute burst 10 packets log prefix "nft-drop: "
  }
  chain forward { type filter hook forward priority 0; policy drop; }
  chain output  { type filter hook output  priority 0; policy accept; }
}

03 Güvenli şekilde uygulayın

Schedule a flush before applying, so a mistake resolves itself rather than requiring the console.

echo 'nft flush ruleset' | at now + 10 minutes
nft -f /etc/nftables.conf
# verify you are still connected, then:
atrm $(atq | cut -f1)
systemctl enable nftables

04 ICMPv6'yı asla engellemeyin

IPv6 depends on ICMPv6 for neighbour discovery and path MTU discovery. Blocking it wholesale, which people do out of IPv4 habit, produces intermittent failures that are extremely hard to diagnose.

Sık sorulan sorular

nftables mı yoksa ufw mu kullanmalıyım?

ufw is a friendlier front end and handles both address families correctly by default. Use nftables directly when you need rules ufw cannot express, such as rate limiting or NAT.

Nelerin reddedildiğini nasıl görebilirim?

Yukarıdaki günlük kuralı, "nft-drop" önekiyle çekirdek günlüğüne yazar; journalctl -k -g nft-drop ile okuyun.