Look at this tutorial of @qubist :
And this one to configure sys-dns and sys-wall to change nftable instead of iptable:
It’s what i use