For example, on my OpenBSD firewall I can write the following simple rules to restrict outbound Internet access to a specific set of IP addresses or networks:
# internal_if is the LAN-facing interface; isp_if is the ISP-facing interface, i.e., the Internet.
match in log on internal_if from <internet_allowed_networks> tag OUTBOUND
pass in log quick on internal_if tagged OUTBOUND
...
pass out log on isp_if inet tagged OUTBOUND nat-to (isp_if) static-port
The tags are sticky, so that you can apply multiple tags to packets and sort through the tags later in the pipeline.If nftables supports something like this, I'll probably make the switch, as I prefer Linux in every other way to OpenBSD.
For me nftables changed the game for linux firewalls. From the almost incomprehensible mess that was iptables we now have a clean language that lets me be quite DRY, and is easy to work with.
1: https://wiki.nftables.org/wiki-nftables/index.php/Setting_pa...
You apparently never had to deal with ipchains or ipfwadm. iptables was a huge upgrade!
If people are using marks for policy-based firewalls a la tag in pf, it doesn't look like a particularly common practice, based on a quick Google search. Anyway, it's a start. Thanks for the pointer.