Guideschevron_rightServers

Servers · 7 min read · Updated

UFW vs firewalld vs iptables vs nftables

iptables and nftables are the two ways of writing packet filtering rules into the Linux kernel; nftables is the newer one and what current distributions use underneath. UFW and firewalld are front ends: they take simple commands such as “allow SSH” and write the kernel rules for you. Use UFW on Ubuntu and Debian, firewalld on AlmaLinux, Rocky Linux and other Red Hat-family systems, and nftables directly only when you need rules the front ends cannot express. Never run two of them at once.

Side by Side

UFW, firewalld, iptables and nftables compared
AspectUFWfirewalldiptablesnftables
What it isFront endFront endRule language and tool (older)Rule language and tool (current)
Where it is standardUbuntu (installed, off by default)AlmaLinux, Rocky Linux, RHEL, FedoraOlder systems; kept for compatibilityUnderneath current Debian, Ubuntu and RHEL
How you workufw allow 443/tcpZones and servicesOne rule per command, per tableA whole ruleset in one file
IPv4 and IPv6Both, from one commandBoth, from one commandSeparate tools (iptables, ip6tables)One ruleset for both
Changes applyAt onceRuntime, or --permanent then reloadAt once, lost on reboot unless savedAtomically when the file is loaded
Choose it whenA simple server on Ubuntu or DebianA Red Hat-family serverFollowing old instructionsYou need sets, maps or full control

The Kernel Layer: iptables and nftables

The filtering itself happens in the kernel's netfilter framework. iptables was its interface for two decades, with separate commands for IPv4, IPv6 and ARP and rules added one at a time. nftables replaced it with a single tool, a proper rule language, sets of addresses and ports, and atomic updates: a whole ruleset is loaded at once, so there is never a moment with half the rules in place.

On current systems the iptables command is usually a compatibility layer that writes nftables rules. Check which you have:

iptables -V          # "nf_tables" = the compatibility layer, "legacy" = old iptables
sudo nft list ruleset   # every rule actually loaded, whoever wrote it

UFW

UFW (Uncomplicated Firewall) is Ubuntu's front end. It is installed but inactive on a fresh server. Allow SSH before turning it on, or you will lock yourself out:

sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo ufw status verbose

It is the easiest choice for a single server, and first steps on a new Linux server uses it. One known catch: ports published by Docker skip UFW's rules entirely, which UFW not working with Docker explains.

firewalld

firewalld is the standard on AlmaLinux, Rocky Linux, RHEL and Fedora. It groups interfaces into zones (such as public) and opens named services in them. Changes made without --permanent last only until the next reload, which is useful for testing:

sudo firewall-cmd --get-active-zones
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

nftables Directly

Writing nftables yourself makes sense when you want one readable file for the whole firewall, or need sets (“these 40 addresses may reach port 5432”) and rate limits. The rules live in /etc/nftables.conf and load at boot with systemctl enable --now nftables. Disable UFW or firewalld first so nothing overwrites them.

Rules That Apply to All of Them

  • Use one tool. Two front ends, or a front end plus hand-written rules, end in rules nobody can explain.
  • Allow SSH (or Remote Desktop) before enabling anything with a default-deny policy.
  • Keep a way in that does not depend on the network. On Virteche Cloud, the browser console on the server's page works even when the firewall blocks everything.
  • Test from outside the server: a port that looks closed from the server itself may still be open to the internet.

A firewall in front of the server adds a second layer. The one in the Virteche Cloud dashboard runs on the host, so traffic you block never reaches the server at all, even if a rule inside it is wrong.

Common Questions

  • Is nftables replacing iptables?

    Yes. nftables is the newer packet filtering framework in the Linux kernel, and current Debian, Ubuntu and Red Hat releases build on it. The iptables command still exists, but on those systems it is usually iptables-nft, which translates iptables rules into nftables underneath.

  • Can I use UFW and firewalld together?

    No. Both manage the same kernel rules and will overwrite or contradict each other. Pick the one your distribution uses, disable the other, and make every change through that one tool.

  • Should I use UFW on Ubuntu?

    For most single servers, yes. It is installed on Ubuntu, its commands are short, and it covers the common case of allowing a few ports. Use nftables directly when you need rules UFW cannot express.

  • How do I see which one my server is using?

    Run ufw status and systemctl is-active firewalld to see whether either front end is on, nft list ruleset to see the rules actually loaded, and iptables -V, which says nf_tables or legacy depending on the backend.

Every Virteche Cloud VPS also has a free firewall on the host, managed from the dashboard and enforced before traffic reaches your server.

See VPS plans

Keep Reading

All guides
UFW vs firewalld vs iptables vs nftables | Virteche Cloud