well nftables is the future and IMO the better choice for ease of control too. It’s been the official successor since 2014 and every major distro defaults to it now, or uses iptables-nft as a compatibility shim. Even firewalld and UFW use it as their backend. So it’s arguably better time spent to focus on nftables.