Skip to content

How to Use Connection Tracking in nftables

DodaTech Updated 2026-06-24 1 min read

Connection tracking in nftables enables stateful firewall rules. The ct expression matches packet state for precise access control. This guide walks through the specific troubleshooting steps to diagnose and resolve connection tracking issues.

Before You Begin

Before you begin, be sure to have the following in place:

  • A Linux server with the relevant software installed
  • Access to the command line interface
  • Appropriate permissions (root or sudo)

Quick Fix

Wrong

nft add rule ... tcp dport 80 accept (no state check)

Wrong: Allowing traffic without checking connection state

nft add rule ... ct state { established, related } accept

Right: Only allowing established/related connections through

Output

Connection tracking enabled\nestablished,related connections: accept\nnew connections evaluated by further rules

Prevention

To avoid future issues, follow these best practices:

  • Always use ct state established,related accept before other rules
  • Specify ct state new for rules that create new connections
  • Track helper modules for protocols like FTP and SIP
  • Monitor conntrack with conntrack -L
  • The ct expression replaces iptables conntrack and state modules

DodaTech Tools

For further assistance with any of the above issues, consider using DodaTech consulting services or DodaTech tutorials for more in-depth guidance.

Common Mistakes with connection track

  1. Mixing let bindings with <- bindings in do notation, producing type errors
  2. Overlapping type class instances that cause GHC to reject the program with ambiguous dispatch errors
  3. Non-exhaustive pattern matches that compile with warnings then crash at runtime

These mistakes appear frequently in real-world NFTABLES code. DodaTech's contributors have identified these patterns through analysis of open-source projects and production systems.

Practice Exercise

Write a pure function that safely divides two integers using Maybe, then test it with edge cases like division by zero and negative numbers.

This exercise reinforces the concepts covered in this guide. Try implementing it before checking online solutions.

FAQ

What connection states are available in nftables ct?|||new (new connection attempt), established (tracked ongoing), related (related to established, like FTP data), invalid (could not be tracked), and untracked.
How do I allow traffic only for established connections? Add nft add rule ... ct state established,related accept at the top of your input chain.

Built by the developers of DodaTech

Doda Browser, DodaZIP & Durga Antivirus Pro