↑ ↓ select, Enter open, Esc close

Show the complete nftables ruleset with handles

root@server
nft -a list ruleset

Shows the entire active ruleset in the netfilter kernel, including rules created by ufw, Fail2Ban, Docker or iptables-nft. The -a option appends # handle N to each rule. With this number, a single rule can be removed via nft delete rule <familie> <tabelle> <kette> handle N (family, table, chain).

Note: On Debian 12 and Ubuntu 24.04, iptables is only a translation layer on top of nftables, which is why iptables rules appear here as tables ip filter or ip6 filter.

Also searched as

  • nft list ruleset
  • show all firewall rules nftables
  • delete nftables rule by handle

Related one-liners

All in Firewall

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.