Linux Command: iptables
Configure Linux kernel packet filtering firewall rules
iptables is the traditional Linux firewall tool that manages packet filtering rules in the kernel. It controls incoming, outgoing, and forwarded network traffic using chains (INPUT, OUTPUT, FORWARD) and tables (filter, nat, mangle). iptables is powerful but complex โ each rule must be specified precisely. Modern distributions often provide friendlier frontends like ufw (Ubuntu) or firewall-cmd (RHEL), but understanding iptables is essential for advanced networking. iptables rules are not persistent by default โ they are lost on reboot unless saved with iptables-save and restored with iptables-restore.
Syntax
iptables [OPTION]... [CHAIN] [RULE]Key Options
-Aโ Append rule to chain-Iโ Insert rule at position-Dโ Delete rule-Lโ List rules-Fโ Flush (delete all rules)-Pโ Set default policy
Examples
List all rules
sudo iptables -L -v -n --line-numbersAllow SSH
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPTAllow web traffic
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT && sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPTPro Tips
- iptables rules are lost on reboot. Save with iptables-save and restore with iptables-restore. Install iptables-persistent on Debian/Ubuntu.
- Rules are evaluated top-down. Place specific rules before general ones. A DROP at the top blocks everything below.
- For simple firewall needs, ufw (Ubuntu) or firewall-cmd (RHEL) are much easier. Learn iptables for advanced scenarios.
Learn more: Full iptables reference โ
Related Resources