Home / Alt manpages / arptables-nft-save(8)

  • arptables-nft-save(8)
  • Admin command
  • linux

Back Up nft-Based ARP Rules with arptables-nft-save

Before you touch a live ARP filter you want a way back, and arptables-nft-save dumps the current nft-based ruleset to a file you can restore from. You will dump the table to a reviewable file, optionally keep packet and byte counters, and verify the backup was actually written. The examples use arptables-nft-save from iptables 1.8.10, package version 1.8.10-3ubuntu2.

Allow about ten minutes. You need the iptables package and a shell. Reading the live ruleset normally needs elevated privileges, so reach for sudo only once an ordinary probe reports permission denied. This guide reads state and writes a backup file; it never alters the firewall.

1. Confirm the nft-based command

Check which executable will run and record the installed package version. These checks change nothing:

$ command -v arptables-nft-save
/usr/sbin/arptables-nft-save
$ dpkg-query -W -f='${Package} ${Version}\n' iptables
iptables 1.8.10-3ubuntu2
$ arptables-nft-save --version
arptables-nft-save v1.8.10 (nf_tables)

This is one of the multi-call nftables tools shipped by iptables. The name matters: this is the nft-based implementation, and it makes no promise of matching an older legacy arptables backend byte for byte.

Checkpoint

Keep this version output with the backup's change record. A restore file is only useful once you know which tool produced it and which host state it represents.

2. Test access without saving yet

Run a read-only save to standard output, redirecting to the terminal only for a quick access check:

$ arptables-nft-save
arptables-nft-save v1.8.10 (nf_tables): Could not fetch rule set generation id: Permission denied (you must be root)

The exact diagnostic depends on the host; here, the unprivileged command exits with status 4 and cannot fetch the nftables ruleset generation ID. Check the status right away if you are troubleshooting:

$ printf 'exit status: %s\n' "$?"
exit status: 4

If rules print instead, you already have enough access for this operation, so do not add sudo just because the command is firewall-related. If access is denied, repeat the save as a privileged account: the privilege is for reading the kernel ruleset, not changing it.

3. Save the current rules to a new file

Choose a directory with suitable permissions and a destination that does not already hold a backup you need. Shell redirection truncates an existing file before the program even finishes, so use a temporary name for anything that matters:

$ umask 077
$ sudo arptables-nft-save > /path/to/arp-rules.nft.tmp
$ test -s /path/to/arp-rules.nft.tmp
$ mv -- /path/to/arp-rules.nft.tmp /path/to/arp-rules.nft

Swap in an existing directory you own or that the command can write to. The umask makes the new file private to its owner. The final mv only fires once the command has returned success and the temporary file is non-empty, and it is not a transaction across filesystems, so keep the temporary and final files in the same directory.

Checkpoint

Inspect the result without editing it:

$ stat --printf='size=%s bytes, mode=%A\n' /path/to/arp-rules.nft
size=... bytes, mode=-rw-------
$ sed -n '1,40p' /path/to/arp-rules.nft

Size and content depend on the host. An empty file is not a useful backup; if the command failed, the temporary file may be missing or incomplete, so never rename it over a known-good copy.

4. Include counters when the snapshot needs them

By default the dump describes rules without current packet and byte counter values. Add --counters when those numbers belong in an incident record or audit snapshot:

$ sudo arptables-nft-save --counters > /path/to/arp-rules-with-counters.nft.tmp
$ test -s /path/to/arp-rules-with-counters.nft.tmp && \
  mv -- /path/to/arp-rules-with-counters.nft.tmp /path/to/arp-rules-with-counters.nft

Counters are live values at the moment you read them and can shift while the command runs, so never treat them as a precise traffic measurement. Save the plain ruleset and the counter-bearing snapshot separately if you need both.

Do not pass --help expecting a usage screen; this binary rejects that option. Use man arptables-nft-save for the documented interface and --version for version information.

5. Supply a modprobe path only when required

-M or --modprobe supplies the path to the modprobe program. Normally this tool reads the executable path from /proc/sys/kernel/modprobe, so most saves should leave the option out entirely:

$ cat /proc/sys/kernel/modprobe
/usr/sbin/modprobe
$ sudo arptables-nft-save --modprobe /usr/sbin/modprobe > /path/to/arp-rules.nft.tmp

Use an explicit path only when the host's kernel setting is unsuitable, or a controlled troubleshooting test calls for it. Verify the file first:

$ test -x /usr/sbin/modprobe && echo 'modprobe is executable'
modprobe is executable

Changing /proc/sys/kernel/modprobe is outside the scope of this guide and can affect other kernel module operations. Do not touch it just to make a routine backup work.

6. Keep the backup safe for a later restore

A saved ruleset earns its keep because arptables-nft-restore can read it from standard input or a file. Restore is a separate, service-affecting operation: its manual page says it flushes the previous ARP table contents. Never test it on production just to prove the file parses.

Protect the backup from casual edits and record where it came from:

$ sha256sum /path/to/arp-rules.nft
...  /path/to/arp-rules.nft
$ sudo arptables-nft-save --version
arptables-nft-save v1.8.10 (nf_tables)

Recovery

If you later need to restore, take a fresh save of the current rules first, then schedule the restore in a maintenance window against a confirmed file and host. There is no general undo for a restore, only another known-good restore or a manually rebuilt ruleset, so keep this backup untouched rather than overwriting it with a failed experiment.

Done means

  • You confirmed that arptables-nft-save is the installed nft-based iptables command and recorded its version.
  • You distinguished an access failure from an empty ruleset by checking the command status and output file.
  • You saved to a new, private file through a temporary name before renaming it.
  • You used --counters only when live packet and byte values belong in the snapshot.
  • You left the live ARP rules unchanged and understand that restore flushes previous contents.