I personally stick to iptables. nftables does not seem to be an improvement at all. iptables is terse but logical.