Nftables
From wikinotes
Designed by netfilter, to replace iptables.
Interfaces that normally had different cli commands are now all merged in one command (ex: iptables, ip6tables, arptables, ...).
nftables also introduces 1st tier tracing utilities to debug rules.
NOTE:
in nftables, unlike pf, the first matching rule is applied
Documentation
Locations
/etc/nftables.conf
ruleset dmesg
journalctl --dmesg
logging (requires 'LOG' rule) (grep-able)
Tutorials
compare nftables to iptables https://linux-audit.com/differences-between-iptables-and-nftables-explained/
Notes
nftables install nftables usage nftables logging nftables syntax