For example, on my OpenBSD firewall I can write the following simple rules to restrict outbound Internet access to a specific set of IP addresses or networks:
# internal_if is the LAN-facing interface; isp_if is the ISP-facing interface, i.e., the Internet.
match in log on internal_if from <internet_allowed_networks> tag OUTBOUND
pass in log quick on internal_if tagged OUTBOUND
...
pass out log on isp_if inet tagged OUTBOUND nat-to (isp_if) static-port
The tags are sticky, so that you can apply multiple tags to packets and sort through the tags later in the pipeline.If nftables supports something like this, I'll probably make the switch, as I prefer Linux in every other way to OpenBSD.