Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use iptables to inspect, add, change, and remove Linux firewall rules for IPv4; use ip6tables for IPv6. The safest workflow is to inspect the active rules, save a rollback copy, make a narrowly scoped change, and verify the result. Be especially careful with rule order and default policies: an incorrect change can expose a service or cut off your remote SSH session.

How iptables processes rules

iptables and ip6tables manage packet-filtering and NAT rules in the Linux kernel. A rule has match criteria and a target. Rules run in order within a chain: if a packet does not match, evaluation moves to the next rule; a matching target decides what happens next. ACCEPT permits the packet, DROP discards it, and RETURN leaves a user-defined chain and resumes evaluation in the calling chain. REJECT actively rejects matching traffic.

The filter table is the default, so ordinary filtering commands do not need a table selector. Use -t nat when working with NAT rules. A match module such as conntrack describes which packets match; it is not itself a target. The available matches and targets depend on the installed iptables build and kernel modules.

The current manual entry cited here is for iptables/ip6tables 1.8.13. Distributions may ship another version or an nft-backed implementation, so check the installed version and behavior rather than assuming every extension is available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect the rules before changing anything

1. Show the installed version

sudo iptables --version

Use the output to identify the installed command implementation before relying on extension behavior.

2. List filter rules with counters and numeric addresses

sudo iptables -L -v -n

-L lists rules, -v shows verbose details and counters, and -n avoids reverse-DNS lookups. This is a useful first view of the default filter table.

3. List one chain

sudo iptables -L INPUT -v -n

Limit inspection to a named chain when you need to focus on incoming traffic.

4. Print rules in command form

sudo iptables -S

-S prints rules in a form that is easier to review or reconstruct than the default listing. Read this before deleting or replacing rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. List NAT rules

sudo iptables -t nat -L -v -n

The -t nat selector matters: without it, listing commands inspect the default filter table, not NAT.

Add, check, and change rules

6. Append an allow rule for SSH

sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT

-A appends to the end of INPUT. This permits matching TCP traffic to port 22 only if evaluation reaches this rule; put specific allows before a later drop rule or policy.

7. Insert a rule at the beginning of a chain

sudo iptables -I INPUT 1 -s 203.0.113.10 -j ACCEPT

-I inserts at a specified rule number, and numbering begins at 1. This example allows packets from the example address at the head of INPUT. Inserting changes the numbering of subsequent rules.

8. Check whether a rule exists

sudo iptables -C INPUT -p tcp --dport 22 -j ACCEPT

-C checks for a matching rule without changing the ruleset. Its exit status indicates whether the rule was found, which makes it useful in scripts that should avoid adding duplicates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. Delete a rule by its full specification

sudo iptables -D INPUT -p tcp --dport 22 -j ACCEPT

-D can remove a rule by matching its specification. Use the same chain and rule details you intend to remove.

10. Delete a rule by number

sudo iptables -D INPUT 3

Rule numbers start at 1. List the chain immediately before deleting by number: any prior change may have shifted the numbering.

11. Replace a rule

sudo iptables -R INPUT 3 -p tcp --dport 443 -j ACCEPT

-R replaces the rule at the specified position. Confirm the current rule number first; replacing the wrong entry can unexpectedly alter access.

Build and remove custom chains

12. Create a user-defined chain

sudo iptables -N WEB_SERVICES

-N creates a chain in the selected table, which is the filter table unless another table is specified.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

13. Jump from INPUT to the custom chain

sudo iptables -A INPUT -p tcp -j WEB_SERVICES

A jump transfers evaluation to the user-defined chain. In this example, matching TCP packets enter WEB_SERVICES and are evaluated against its rules.

14. Return from the custom chain

sudo iptables -A WEB_SERVICES -j RETURN

RETURN ends traversal of the current user-defined chain and resumes at the rule after the jump in the calling chain. It does not mean “accept.”

15. Delete an unused custom chain

sudo iptables -X WEB_SERVICES

Remove references to the chain before deleting it. A chain that is still referenced is not unused.

Flush rules and reset counters

16. Flush one chain

sudo iptables -F INPUT

-F removes all rules from the selected chain. This can disrupt access if that chain was enforcing a firewall policy.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

17. Flush all chains in the default table

sudo iptables -F

With no chain specified, -F flushes all chains in the selected table. Since no table is selected here, that means the filter table. Do not use this as a casual cleanup command on a host you rely on.

18. Zero packet and byte counters

sudo iptables -Z INPUT

-Z resets counters for the selected chain. List the counters first if you need to retain the previous interval’s values, then reset before measuring a new interval.

Set policies and common filtering rules

19. Set the default INPUT policy to DROP

sudo iptables -P INPUT DROP

A built-in chain policy applies to packets that reach the end of the chain without hitting a terminating rule. Before setting a restrictive policy, add and verify the management-access rules you need. A mistaken policy change can lock you out of a remote system.

20. Allow loopback traffic

sudo iptables -A INPUT -i lo -j ACCEPT

This allows traffic arriving on the loopback interface. Under a restrictive policy, make sure the rule appears before a rule or policy that would otherwise drop the traffic.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

21. Allow established and related connections

sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

The conntrack match permits return traffic for connections already tracked as established or related. The match extension must be available in the installed build.

22. Reject new HTTP traffic

sudo iptables -A INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -j REJECT

This matches new TCP connections to port 80 and actively rejects them. Choose REJECT deliberately when an explicit response is appropriate; it behaves differently from silently discarding packets with DROP.

23. Log matching packets before the final decision

sudo iptables -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables dropped: "

Place a logging rule before the later rule or policy that handles the packet. The limit reduces the risk of flooding system logs; required match and target modules must be available. A log target records matching packets but does not itself decide whether to accept or drop them.

Apply NAT and save or restore rules

24. Masquerade outbound traffic in the NAT table

sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

This example adds a masquerade target to the NAT table’s POSTROUTING chain for traffic leaving through eth0. Confirm that interface name and the host’s routing design before applying it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

25. Save and restore the ruleset

sudo iptables-save -c > /etc/iptables/rules.v4
sudo iptables-restore < /etc/iptables/rules.v4

iptables-save emits a parseable ruleset; -c includes packet and byte counters. iptables-restore reads that format back. Protect the saved file because it contains the firewall configuration, and validate restoration in a maintenance window. Saving or restoring rules does not by itself establish that a distribution will reload them automatically at boot.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Make changes safely, especially over SSH

  • Inspect the relevant table and chain with -L -v -n or -S before editing.
  • Save a rollback copy with iptables-save before destructive changes such as flushing a chain or changing a policy.
  • Use the narrowest operation that fits: check with -C, insert or append one rule, then verify its position and effect.
  • Keep a working management path while changing remote firewall rules. Add and verify SSH access before applying a policy that could block it.
  • Use ip6tables as appropriate for IPv6; a change to IPv4 rules alone does not administer the IPv6 ruleset.
  • Confirm the table context. Commands without -t operate on the filter table, while NAT examples need -t nat.

Troubleshooting common iptables problems

A rule appears to have no effect

Check whether an earlier rule matches first, whether the rule is in the intended chain, and whether you selected the correct table. Rule order controls evaluation; an appended allow can be unreachable behind an earlier terminating drop or reject.

A command reports an unknown match or target

The extension may not be available in the installed iptables build or kernel modules. Check sudo iptables --version and the installed system’s supported extensions rather than assuming that a command works identically across distributions.

A deletion or replacement affects the wrong rule

Rule numbers change after insertions and deletions. List the chain immediately before using -D chain number or -R chain number; where practical, delete by the full rule specification instead.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Remote access stops working after a policy change

A restrictive built-in policy can block packets that reach the end of the chain. If you still have console or another out-of-band access path, use it to restore the saved ruleset with iptables-restore. Without an alternate access path, recovery may require provider or physical console access; plan that route before making the change.

A NAT command does not match the network setup

Verify that the interface in -o is the actual egress interface and that masquerading belongs in the host’s routing design. The example is not a universal substitute for checking routes and interfaces.

Or skip the browser setup

For website screenshots rather than Linux firewall rules, ScreenshotNeo is a website screenshot API and MCP server for developers. One GET request can return a PNG, JPEG, WebP, or PDF. Before capture, it accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for AI agents and MCP clients.

Example cURL request, with the API key kept private:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for API options and response details. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo free.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.