# Firewall rules (iptables) not working on Rocky Linux 8 with nftables

**URL:** <https://forums.rockylinux.org/t/firewall-rules-iptables-not-working-on-rocky-linux-8-with-nftables/18467>\
**Category:** Rocky Linux Help & Support\
**Tags:** rocky-linux-8\
**Created:** [May 14, 2025, 10:13pm UTC](https://forums.rockylinux.org/t/firewall-rules-iptables-not-working-on-rocky-linux-8-with-nftables/18467 "2025-05-14T22:13:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vic23](https://avatars.discourse-cdn.com/v4/letter/v/8797f3/32.png) [@vic23](https://forums.rockylinux.org/u/vic23)\
**Post date:** [May 14, 2025, 10:13pm UTC](https://forums.rockylinux.org/t/firewall-rules-iptables-not-working-on-rocky-linux-8-with-nftables/18467/1 "2025-05-14T22:13:21Z")

</div>

Hello,

I am facing an issue when trying to apply firewall rules on Rocky Linux 8.10, where the traffic redirection (DNAT) rules that work correctly on CentOS 7 using `iptables` are not functioning on Rocky Linux 8.10, which uses `nftables` by default.

**Environment Configuration:**

- Operating system: Rocky Linux 8.10
- Firewall: `nftables` (enabled by default on Rocky Linux 8.10)
- Firewall rules I am trying to apply:
  - Redirect TCP traffic arriving at port 5432 (PostgreSQL) from a specific IP (192.168.0.101) to another IP in the same network (192.168.0.102) and to the destination machine (192.168.0.103).

**Problem Description:**  
On CentOS 7, I am able to apply the rules successfully using `iptables`, and the traffic is redirected correctly. However, when I apply the same rules on Rocky Linux, the traffic is not being redirected as expected.

On Rocky Linux, the system is using `nftables`, and when I try to apply the rules through `iptables` (whether using `iptables` or `iptables-nft`), they do not seem to work properly.

**Steps I’ve taken so far:**

1. I enabled IP forwarding with the line `net.ipv4.ip_forward = 1` in the `/etc/sysctl.conf` file and applied it with `sysctl -p`, ensuring IP forwarding is enabled.

2. I made sure the necessary modules for both `iptables` and `nftables` are loaded, including `nf_conntrack`, `nf_conntrack_ipv4`, and `nf_nat`.

3. I tested the rules using the `iptables-nft` command and also tried configuring directly with `nft` (but with no success).

4. I tried disabling `nftables` to use only `iptables`, but the issue persists.

5. firewalld disabled and mask.

**Firewall rules I am applying (iptables on CentOS 7):**

bash

CopiarEditar

```auto
# Enable IP forwarding (if not already done)
sysctl -w net.ipv4.ip_forward=1

# Add rule to redirect traffic from IP 192.168.0.101 on port 5432 to 192.168.0.103 on the same port
iptables -t nat -A PREROUTING -p tcp --dport 5432 -s 192.168.0.101 -j DNAT --to-destination 192.168.0.103:5432

# Ensure that the response to redirected traffic is sent back correctly
iptables -t nat -A POSTROUTING -p tcp --dport 5432 -d 192.168.0.103 -j MASQUERADE

```

**Observed errors:**

- No explicit errors in system logs, but the traffic is not being redirected as expected.

**Questions:**

1. Has anyone encountered similar issues when using `nftables` instead of `iptables` on Rocky Linux 8?
2. Is there any special configuration I should perform to ensure that `iptables` rules work properly with `nftables` on Rocky Linux?
3. Is it possible that the versions of `nftables` and `iptables` on Rocky Linux 8 are causing some conflict? How can I resolve this?
4. Are there any other details or dependencies that might be affecting traffic redirection on Rocky Linux 8?

I would appreciate any guidance or suggestions to resolve this issue.

Best regards,

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [May 15, 2025, 12:50pm UTC](https://forums.rockylinux.org/t/firewall-rules-iptables-not-working-on-rocky-linux-8-with-nftables/18467/2 "2025-05-15T12:50:41Z")

</div>

The tool ‘iptables’ is a wrapper/translator that reads your “iptables syntax” and creates equivalent nftables rules into the kernel. The translation is said to not be 100% complete.

You can see all the rules that are in the kernel with:

```bash
nft list ruleset

```

* * *

Did you also allow traffic to go through in _forward filter_ with something like `ct status dnat accept`  
(or `ip daddr 192.168.0.103 tcp dport 5432 accept`)?

---

<div class="post-metadata">

**Author:** ![vic23](https://avatars.discourse-cdn.com/v4/letter/v/8797f3/32.png) [@vic23](https://forums.rockylinux.org/u/vic23)\
**Post date:** [May 15, 2025, 1:22pm UTC](https://forums.rockylinux.org/t/firewall-rules-iptables-not-working-on-rocky-linux-8-with-nftables/18467/3 "2025-05-15T13:22:54Z")

</div>

I didn’t just write in iptables, and I noticed that the failure occurs and it doesn’t forward, I’m going to rewrite it in nftables now, following the new standard to validate

---

<div class="post-metadata">

**Author:** ![vic23](https://avatars.discourse-cdn.com/v4/letter/v/8797f3/32.png) [@vic23](https://forums.rockylinux.org/u/vic23)\
**Post date:** [May 19, 2025, 9:11pm UTC](https://forums.rockylinux.org/t/firewall-rules-iptables-not-working-on-rocky-linux-8-with-nftables/18467/4 "2025-05-19T21:11:13Z")

</div>

I rewrote the rules in nftables and it worked, the iptables-legacy → nftables integration is not 100% working, I am handling rules in iptables-legacy, until I convert them all to nftables.

Thanks for the support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [July 18, 2025, 9:11pm UTC](https://forums.rockylinux.org/t/firewall-rules-iptables-not-working-on-rocky-linux-8-with-nftables/18467/5 "2025-07-18T21:11:26Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
