Debian firewall options control which network connections can reach a desktop or server. The main choice is not only between nftables, UFW, and firewalld. It also involves choosing a management level. nftables works close to the Linux firewall system, while UFW and firewalld provide higher-level ways to create and manage rules.
The right option depends on your experience, the services exposed by the system, and how often the firewall configuration changes. A beginner desktop user usually needs a simple interface. An administrator managing several services may need more control and clearer separation between temporary and permanent changes.
Table of Contents
How the three firewall options differ
| Tool | Management level | Best suited to | Main consideration |
|---|---|---|---|
| nftables | Direct rule management for the Linux firewall system | Administrators who need precise rules | More powerful, but easier to misconfigure |
| UFW | Simple command-line interface for common firewall rules | Beginner desktop users and straightforward servers | Less complex to use, with fewer management features |
| firewalld | Policy manager with zones and service-based rules | Systems with changing network roles or several trust levels | Requires understanding zones, services, and rule state |
nftables is not the same type of tool as UFW or firewalld. nftables is used to define firewall rules directly. UFW and firewalld manage firewall rules through their own commands and configuration models. Installing or using one does not mean that all three should be configured at the same time.
nftables for direct and detailed control
nftables is appropriate when you need exact control over traffic. It can express rules for addresses, ports, protocols, interfaces, connection states, and IPv4 or IPv6 traffic. This makes it a strong choice for administrators who already understand firewall policy and want a configuration that matches the system design closely.
The extra control also increases the troubleshooting effort. A small error in a rule or chain can block a required service, including SSH. Rules should be planned before they are applied, and remote administrators should keep console or out-of-band access available when possible.
For a persistent nftables setup, save the intended rules in the system configuration and ensure the related service loads them during boot. Check the active rules with:
sudo nft list ruleset The displayed ruleset is the useful source of truth when checking what the kernel is currently applying. A configuration file that was edited but not loaded does not represent the active firewall.
UFW for simple desktop and server policies
UFW is designed to make common firewall tasks easier to express. It is often a suitable starting point for a Debian desktop or a small server with a limited set of services. You can allow or deny traffic by service, port, address, or direction without writing the complete lower-level ruleset yourself.
UFW is a good fit when the policy is stable and simple. For example, a server may need SSH access and one or more web services, while other incoming connections remain blocked. It is less suitable when the policy needs advanced traffic processing or a large number of separate network conditions.
Check whether UFW is active and review its current policy with:
sudo ufw status verbose Before enabling UFW on a remote server, allow the SSH service or the actual SSH port first. Keep the current session open while testing a new policy. A rule that blocks the management connection can prevent further remote access even when the firewall itself is working as configured.
firewalld for zones and changing network roles
firewalld manages firewall policy through zones. A zone represents a level of trust for a network connection, and services or ports can be allowed within that zone. This model can help when a system uses different interfaces or changes between network environments.
firewalld separates runtime changes from permanent configuration. A runtime rule affects the current firewall state. A permanent rule is intended to remain after a reload or restart. A change that was made only at runtime may disappear later, so check that important changes are saved in the intended form.
Useful checks include:
sudo firewall-cmd --state
sudo firewall-cmd --get-active-zones
sudo firewall-cmd --list-all firewalld can be more than a beginner needs for one simple network. It becomes useful when the system has several interfaces, changing trust levels, or a policy managed through service names and zones.
IPv6 rules and firewall coverage
IPv6 must be included in the firewall plan. A rule that protects IPv4 traffic does not automatically prove that IPv6 traffic is covered. Check how the selected tool handles both address families, and review the active rules rather than only the configuration file.
With nftables, the rule design can distinguish between IPv4 and IPv6 or use a family that covers both. With UFW, IPv6 support depends on its IPv6 configuration. With firewalld, review the active zone and its rules for the relevant address family. If IPv6 is enabled on the system, test the services over IPv6 as well as IPv4.
Which Debian firewall tool should you choose?
- Choose UFW for a beginner desktop user or a small server with a short, stable list of allowed services.
- Choose firewalld when the system has several network interfaces, changing network roles, or a need to manage policy with zones and services.
- Choose nftables when an experienced administrator needs precise rules, advanced conditions, or direct control of the active ruleset.
For any exposed server, document the required services before changing the firewall. Confirm SSH access, include IPv6 where it is enabled, check the active rules after each change, and make the configuration persistent using the selected tool. When a remote system becomes inaccessible, use console access if available and contact support if you cannot restore access safely.