nft add rule inet filter input drop

Category: Security & Hardening

nft add rule inet filter input drop

Drop all remaining packets in the input chain

Adds a catch-all drop as the last rule, so anything not explicitly accepted is discarded silently. In nftables, unlike iptables, you can mix accept and drop rules freely in one chain. Always place it after your accept rules or traffic never reaches them.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.