To block unmatched packets destined for a Linux host while keeping SSH available, allow loopback, allow established and related connections, allow new TCP connections to the host’s actual SSH port, and set the IPv4 INPUT chain policy to DROP. The example below assumes SSH listens on TCP port 22; change that port if your server uses another one.
What these iptables rules do
The INPUT chain handles packets destined for the local host. The FORWARD chain handles packets routed through it, while OUTPUT handles locally generated packets. This recipe changes only INPUT; it does not block forwarded traffic or change the host’s outbound policy. See the iptables(8) manual.
A built-in chain’s policy applies when a packet reaches the end of the chain without matching an earlier terminal rule. Setting INPUT to DROP therefore drops incoming packets not accepted by the rules above it.
Apply the IPv4 rules
First confirm that iptables is the firewall interface in use and identify the SSH daemon’s listening port. An active firewall manager may replace or conflict with manually added rules. These commands are runtime rules; persistence across reboot depends on the distribution and firewall manager.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
-
Allow traffic over the loopback interface:
sudo iptables -A INPUT -i lo -j ACCEPT -
Allow packets belonging to established or related connections:
sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT -
Allow new TCP connections to SSH. Replace
22with the actual listening port if needed:sudo iptables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPTFree tools Windows power users keep installed
One-click scans. No signup required.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Set the built-in
INPUTchain policy to drop unmatched packets:sudo iptables -P INPUT DROP
Rules are evaluated in order, and the chain policy applies only after packets pass through the rules without an earlier terminal verdict. The conntrack extension recognizes states including NEW, ESTABLISHED, RELATED, INVALID, and UNTRACKED; ESTABLISHED traffic has been seen in both directions, while RELATED traffic is associated with an existing connection. The iptables-extensions(8) manual notes that the state extension is a subset of conntrack; the Netfilter state-match documentation describes connection states.
Rank #4
Reduce the risk of locking yourself out
Changing the INPUT policy over SSH can cut off access if the exception does not match the SSH service. Before applying the policy remotely:
-
Verify the SSH listening port and ensure the allow rule uses that TCP destination port.
PerformanceWindows Errors? Fix Them Before They SpreadDriversCrashes, No Sound, or Screen Glitches?PerformancePC Slower Than It Used to Be?Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Best Value
-
Keep a console or other out-of-band recovery path available, or arrange a tested timed rollback.
-
After applying the rules, inspect the installed ruleset and test a second SSH login before closing the current session.
Configure IPv6 separately
The commands above configure IPv4 only. If IPv6 is enabled, IPv6 traffic needs its own intended firewall policy through the active firewall manager or, where appropriate, ip6tables. Verify both address families; an IPv4 INPUT policy does not cover IPv6.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

