# Nftables rules for hardening Discourse installation

**URL:** https://meta.discourse.org/t/nftables-rules-for-hardening-discourse-installation/240591
**Category:** Self-hosting
**Created:** [October 1, 2022, 6:58pm UTC](https://meta.discourse.org/t/nftables-rules-for-hardening-discourse-installation/240591 "2022-10-01T18:58:53Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [October 1, 2022, 7:31pm UTC](https://meta.discourse.org/t/nftables-rules-for-hardening-discourse-installation/240591/2 "2022-10-01T19:31:59Z")

</div>

Hey @OrkoGrayskull did you find

> [@Will UFW limit Discourse too?](https://meta.discourse.org/t/will-ufw-limit-discourse-too/231873/12):
>
> This is actually a really good question and one I’m surprised nobody else has yet asked. The answer is complicated, but so far the responses on this topic have unfortunately been dismissive in tone without answering the question. It isn’t per se that Discourse is bypassing ufw, but docker bypasses ufw by adding rules that cause any exposed ports of docker containers to work despite the presence of ufw. What’s going on? Incoming packets destined for a container hit the FORWARD table, not the IN…

In your searches? There’s a little more backstory there on how docker interacts with firewalls.

---

_[View the full topic](https://meta.discourse.org/t/nftables-rules-for-hardening-discourse-installation/240591)._
