@GNUser
I have just spotted you have nftables on x86_64. Does that need any kernel modules?
Yes, nftables needs several kernel modules. The modules are provided by ipv6-netfilter-KERNEL.tcz, which is a dependency of nftables.tcz.
nftables.tcz is the only extension you need to load. It provides the nft command line tool you need to configure the firewall.
I have no experience at using it...does it work on 17x?
Yes, it's been working perfectly for me since I first tried it with TCL12 Pure64, up until now with TCL17 Pure64.
My wireless router is running TCL17 Pure64, with nftables for firewall. I switched from iptables to nftables back in 2021 and have never looked back: Since the switch, my firewall has been much easier to understand and customize. The only downside is that there still seems to be more documentation/how-tos for iptables than for nftables, but nft is easier to understand and has cleaner syntax than iptables, so that compensates for the relatively scanty online documentation.