Stop nftables from letting you guess which rule is dropping your traffic

Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)

Stop nftables from letting you guess which rule is dropping your traffic

🧩 The Challenge

You are staring at a production server where your curl requests to a new internal API just hang indefinitely. The firewall rules look fine, but somewhere in that massive chain, something is silently black-holing your packets and you have no idea which rule is the culprit.

💡 The Fix

Turn on nftables tracing to see exactly how your packets move through the chains in real-time. It beats staring at firewall logs that aren’t even printing the drop events you need.

nft add rule ip filter input ip saddr 10.0.0.5 meta nftrace set 1
nft monitor trace

⚙️ Why It Works

Setting the nftrace flag on a specific packet flow tells the kernel to report every rule match event back to userspace, which the monitor command then displays directly to your terminal. It basically turns your firewall into a debugger.

🚀 Pro-Tip: Always include a filter for your source or destination IP in the rule so you don’t flood your console with noise from every single connection on the box.

Linux Tips & Tricks | © ngelinux.com | 8/16/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted