Use iptables to inspect, add, change, and remove Linux firewall rules for IPv4; use ip6tables for IPv6. The safest workflow is to inspect the active rules, save a rollback copy, make a narrowly scoped change, and verify the result. Be especially careful with rule order and default policies: an incorrect change can expose a service or cut off your remote SSH session.
How iptables processes rules
iptables and ip6tables manage packet-filtering and NAT rules in the Linux kernel. A rule has match criteria and a target. Rules run in order within a chain: if a packet does not match, evaluation moves to the next rule; a matching target decides what happens next. ACCEPT permits the packet, DROP discards it, and RETURN leaves a user-defined chain and resumes evaluation in the calling chain. REJECT actively rejects matching traffic.
The filter table is the default, so ordinary filtering commands do not need a table selector. Use -t nat when working with NAT rules. A match module such as conntrack describes which packets match; it is not itself a target. The available matches and targets depend on the installed iptables build and kernel modules.
The current manual entry cited here is for iptables/ip6tables 1.8.13. Distributions may ship another version or an nft-backed implementation, so check the installed version and behavior rather than assuming every extension is available.
#1 Best Overall
- Used Book in Good Condition
Inspect the rules before changing anything
1. Show the installed version
sudo iptables --version
Use the output to identify the installed command implementation before relying on extension behavior.
2. List filter rules with counters and numeric addresses
sudo iptables -L -v -n
-L lists rules, -v shows verbose details and counters, and -n avoids reverse-DNS lookups. This is a useful first view of the default filter table.
3. List one chain
sudo iptables -L INPUT -v -n
Limit inspection to a named chain when you need to focus on incoming traffic.
4. Print rules in command form
sudo iptables -S
-S prints rules in a form that is easier to review or reconstruct than the default listing. Read this before deleting or replacing rules.
5. List NAT rules
sudo iptables -t nat -L -v -n
The -t nat selector matters: without it, listing commands inspect the default filter table, not NAT.
Add, check, and change rules
6. Append an allow rule for SSH
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
-A appends to the end of INPUT. This permits matching TCP traffic to port 22 only if evaluation reaches this rule; put specific allows before a later drop rule or policy.
Rank #2
7. Insert a rule at the beginning of a chain
sudo iptables -I INPUT 1 -s 203.0.113.10 -j ACCEPT
-I inserts at a specified rule number, and numbering begins at 1. This example allows packets from the example address at the head of INPUT. Inserting changes the numbering of subsequent rules.
8. Check whether a rule exists
sudo iptables -C INPUT -p tcp --dport 22 -j ACCEPT
-C checks for a matching rule without changing the ruleset. Its exit status indicates whether the rule was found, which makes it useful in scripts that should avoid adding duplicates.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches9. Delete a rule by its full specification
sudo iptables -D INPUT -p tcp --dport 22 -j ACCEPT
-D can remove a rule by matching its specification. Use the same chain and rule details you intend to remove.
10. Delete a rule by number
sudo iptables -D INPUT 3
Rule numbers start at 1. List the chain immediately before deleting by number: any prior change may have shifted the numbering.
11. Replace a rule
sudo iptables -R INPUT 3 -p tcp --dport 443 -j ACCEPT
-R replaces the rule at the specified position. Confirm the current rule number first; replacing the wrong entry can unexpectedly alter access.
Build and remove custom chains
12. Create a user-defined chain
sudo iptables -N WEB_SERVICES
-N creates a chain in the selected table, which is the filter table unless another table is specified.
Recommended Free Tools
Rank #3
13. Jump from INPUT to the custom chain
sudo iptables -A INPUT -p tcp -j WEB_SERVICES
A jump transfers evaluation to the user-defined chain. In this example, matching TCP packets enter WEB_SERVICES and are evaluated against its rules.
14. Return from the custom chain
sudo iptables -A WEB_SERVICES -j RETURN
RETURN ends traversal of the current user-defined chain and resumes at the rule after the jump in the calling chain. It does not mean “accept.”
15. Delete an unused custom chain
sudo iptables -X WEB_SERVICES
Remove references to the chain before deleting it. A chain that is still referenced is not unused.
Flush rules and reset counters
16. Flush one chain
sudo iptables -F INPUT
-F removes all rules from the selected chain. This can disrupt access if that chain was enforcing a firewall policy.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
17. Flush all chains in the default table
sudo iptables -F
With no chain specified, -F flushes all chains in the selected table. Since no table is selected here, that means the filter table. Do not use this as a casual cleanup command on a host you rely on.
18. Zero packet and byte counters
sudo iptables -Z INPUT
-Z resets counters for the selected chain. List the counters first if you need to retain the previous interval’s values, then reset before measuring a new interval.
Set policies and common filtering rules
19. Set the default INPUT policy to DROP
sudo iptables -P INPUT DROP
A built-in chain policy applies to packets that reach the end of the chain without hitting a terminating rule. Before setting a restrictive policy, add and verify the management-access rules you need. A mistaken policy change can lock you out of a remote system.
20. Allow loopback traffic
sudo iptables -A INPUT -i lo -j ACCEPT
This allows traffic arriving on the loopback interface. Under a restrictive policy, make sure the rule appears before a rule or policy that would otherwise drop the traffic.
Free tools Windows power users keep installed
One-click scans. No signup required.
21. Allow established and related connections
sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
The conntrack match permits return traffic for connections already tracked as established or related. The match extension must be available in the installed build.
22. Reject new HTTP traffic
sudo iptables -A INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -j REJECT
This matches new TCP connections to port 80 and actively rejects them. Choose REJECT deliberately when an explicit response is appropriate; it behaves differently from silently discarding packets with DROP.
23. Log matching packets before the final decision
sudo iptables -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables dropped: "
Place a logging rule before the later rule or policy that handles the packet. The limit reduces the risk of flooding system logs; required match and target modules must be available. A log target records matching packets but does not itself decide whether to accept or drop them.
Apply NAT and save or restore rules
24. Masquerade outbound traffic in the NAT table
sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
This example adds a masquerade target to the NAT table’s POSTROUTING chain for traffic leaving through eth0. Confirm that interface name and the host’s routing design before applying it.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
25. Save and restore the ruleset
sudo iptables-save -c > /etc/iptables/rules.v4
sudo iptables-restore < /etc/iptables/rules.v4
iptables-save emits a parseable ruleset; -c includes packet and byte counters. iptables-restore reads that format back. Protect the saved file because it contains the firewall configuration, and validate restoration in a maintenance window. Saving or restoring rules does not by itself establish that a distribution will reload them automatically at boot.
Make changes safely, especially over SSH
- Inspect the relevant table and chain with
-L -v -nor-Sbefore editing. - Save a rollback copy with
iptables-savebefore destructive changes such as flushing a chain or changing a policy. - Use the narrowest operation that fits: check with
-C, insert or append one rule, then verify its position and effect. - Keep a working management path while changing remote firewall rules. Add and verify SSH access before applying a policy that could block it.
- Use
ip6tablesas appropriate for IPv6; a change to IPv4 rules alone does not administer the IPv6 ruleset. - Confirm the table context. Commands without
-toperate on the filter table, while NAT examples need-t nat.
Troubleshooting common iptables problems
A rule appears to have no effect
Check whether an earlier rule matches first, whether the rule is in the intended chain, and whether you selected the correct table. Rule order controls evaluation; an appended allow can be unreachable behind an earlier terminating drop or reject.
A command reports an unknown match or target
The extension may not be available in the installed iptables build or kernel modules. Check sudo iptables --version and the installed system’s supported extensions rather than assuming that a command works identically across distributions.
A deletion or replacement affects the wrong rule
Rule numbers change after insertions and deletions. List the chain immediately before using -D chain number or -R chain number; where practical, delete by the full rule specification instead.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Remote access stops working after a policy change
A restrictive built-in policy can block packets that reach the end of the chain. If you still have console or another out-of-band access path, use it to restore the saved ruleset with iptables-restore. Without an alternate access path, recovery may require provider or physical console access; plan that route before making the change.
A NAT command does not match the network setup
Verify that the interface in -o is the actual egress interface and that masquerading belongs in the host’s routing design. The example is not a universal substitute for checking routes and interfaces.
Or skip the browser setup
For website screenshots rather than Linux firewall rules, ScreenshotNeo is a website screenshot API and MCP server for developers. One GET request can return a PNG, JPEG, WebP, or PDF. Before capture, it accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for AI agents and MCP clients.
Example cURL request, with the API key kept private:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for API options and response details. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo free.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

