Don’t let WireGuard and nftables fight over the same packet
Technical Briefing | 10/3/2026
WireGuard interfaces feel like magic until you start stacking firewall rules on top of them. I’ve spent enough nights watching tunnels refuse to pass traffic simply because nftables was being a bit too aggressive with the reverse path filtering. When you move to nftables, the default drop policies often bite you because WireGuard runs entirely in the kernel and bypasses the traditional socket-based filtering we used to rely on.
The kernel bypass trap
Most sysadmins forget that WireGuard interfaces like wg0 aren’t standard physical interfaces. Because they operate at the peer level, packets entering the interface are already decrypted and essentially look like local traffic to the netfilter hooks. If you have strict egress rules for your default gateway, those same rules often block your tunneled traffic unless you explicitly tell the kernel to handle the wg0 interface differently.
nft add rule inet filter forward iifname wg0 oifname eth0 accept
- Use interface names in your nftables rules instead of IP ranges to handle dynamic client reconnects.
- Ensure your forward chain explicitly allows traffic from the tunnel interface to the exit interface.
- Check your reverse path filtering settings in sysctl since strict mode often kills WireGuard handshake packets.
Why stateful matching saves your sanity
You don’t need a rule for every single handshake packet. By using stateful matching in your forward chain, you allow the return traffic without manually whitelisting every peer endpoint IP. It keeps your ruleset readable, and more importantly, it prevents the inevitable mistake of missing one peer during a config update.
Next time you see a hung tunnel, skip the tcpdump session for a minute and check your forward chain counters. If you see packets hitting the drop rule on the wg0 interface, you know exactly which policy is killing your throughput. Keep your ruleset flat and your interface matching tight, and you’ll spend significantly less time chasing ghost packets.
