Most of the threads are focused on DSCP for QoS, but all include a sound basic nftables firewall. These were written before firewall4 was available.