Firewalls and Network Defense
UFW and nftables Host Firewalls on KaliLinux.net: A Lab Guide
Learn defensive host firewall basics with UFW and nftables on Kali Linux. Configure lab rules, inspect traffic, and harden authorized test environments.

On a Kali workstation, host firewalls tend to get set up once and then ignored until a lab breaks. That is a risky habit becouse Kali boxes often run temporary services, Metasploit listeners, Python HTTP servers, or SSH access for remote management. KaliLinux.net reccomends treating teh local firewall as basic lab hygiene, especially on shared networks, conference Wi-Fi, or multi-VM ranges used for CTF practice. The two main tools on a modern Kali install are UFW and nftables. UFW is a user-friendly frontend for netfilter rules. nftables is the lower-level framework wich has replaced iptables as the default backend in many Debian-based distributions. Neither tool replaces strong authentication or network isolation, but a clean ruleset reduces exposed services quickly.
Why a Kali host needs firewall rules
Kali is not a server distribution, but it still opens ports during everyday lab work. If you run msfconsole with a payload handler, a Python HTTP server for file transfers, or SSH for remote access, those services listen on network interfaces. On a shared lab VLAN an accidental bind to 0.0.0.0 can expose a vulnerable service to other students. A firewall cannot fix weak service configs, but it limits which ports are reachable. Debian 10 Buster, released in July 2019, moved the default iptables backend to nftables. Kali inherits that change, so learning both UFW and nftables is practical for defensive tooling, troubleshooting, and certification study. The key point is not to block everything blindly. The goal is to deny unexpected incoming traffic while allowing the specific ports you need for authorized lab sessions.
Using UFW for fast baseline rules
UFW stands for Uncomplicated Firewall and it lives up to the name. A sensible baseline begins by checking the current state with sudo ufw status verbose. If UFW is inactive, set the defaults before enabling it. sudo ufw default deny incoming drops unsolicited connections. sudo ufw default allow outgoing keeps normal tool updates and outbound lab traffic working. Then allow only required services, such as sudo ufw allow 22/tcp for SSH. Enable the firewall with sudo ufw enable only after you have allowed SSH if the box is remote. This sequence avoids a common mistake: locking yourself out of a headless Kali VM. UFW is often enough for lab work because most of the time a Kali workstation is a client, not a server. It gives you readable rules, quick enable/disable behavior, and a status output that is easy to screenshot for lab reports.
nftables for direct control
nftables is closer to the packet path and more flexible than UFW. It uses tables and chains instead of UFW’s simplified command set. Start with sudo nft list ruleset to inspect active rules. A minimal ruleset defines a table, a base chain, and a policy. For example, you can create an inet filter table and set the input chain policy to drop, then accept related and established traffic. The syntax is more verbose, but it allows advanced features such as IP sets, per-interface rules, NAT, and custom logging. If you are studying network defense or building a vulnerable lab target, direct nftables rules give you precise control over what enters each interface. The netfilter nftables documentation
is a useful reference for the latest syntax. Just remember not to edit UFW-managed chains manually while UFW is active. Pick one tool for a given ruleset or use UFW as the frontend and inspect the resulting nftables rules with sudo nft list ruleset.
For a Kali lab box, the choice is usually practical. UFW covers quick baselines and report screenshots. nftables helps when you need custom chains, sets, or interface-specific rules. Document your rules, test with nmap from localhost and a second authorized lab host, and keep the firewall quiet enough that it does not interfere with legal CTF traffic.