Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To block unmatched packets destined for a Linux host while keeping SSH available, allow loopback, allow established and related connections, allow new TCP connections to the host’s actual SSH port, and set the IPv4 INPUT chain policy to DROP. The example below assumes SSH listens on TCP port 22; change that port if your server uses another one.

What these iptables rules do

The INPUT chain handles packets destined for the local host. The FORWARD chain handles packets routed through it, while OUTPUT handles locally generated packets. This recipe changes only INPUT; it does not block forwarded traffic or change the host’s outbound policy. See the iptables(8) manual.

A built-in chain’s policy applies when a packet reaches the end of the chain without matching an earlier terminal rule. Setting INPUT to DROP therefore drops incoming packets not accepted by the rules above it.

Apply the IPv4 rules

First confirm that iptables is the firewall interface in use and identify the SSH daemon’s listening port. An active firewall manager may replace or conflict with manually added rules. These commands are runtime rules; persistence across reboot depends on the distribution and firewall manager.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Allow traffic over the loopback interface:

    sudo iptables -A INPUT -i lo -j ACCEPT

  2. Allow packets belonging to established or related connections:

    sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

  3. Allow new TCP connections to SSH. Replace 22 with the actual listening port if needed:

    sudo iptables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Set the built-in INPUT chain policy to drop unmatched packets:

    sudo iptables -P INPUT DROP

Rules are evaluated in order, and the chain policy applies only after packets pass through the rules without an earlier terminal verdict. The conntrack extension recognizes states including NEW, ESTABLISHED, RELATED, INVALID, and UNTRACKED; ESTABLISHED traffic has been seen in both directions, while RELATED traffic is associated with an existing connection. The iptables-extensions(8) manual notes that the state extension is a subset of conntrack; the Netfilter state-match documentation describes connection states.

Reduce the risk of locking yourself out

Changing the INPUT policy over SSH can cut off access if the exception does not match the SSH service. Before applying the policy remotely:

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Configure IPv6 separately

The commands above configure IPv4 only. If IPv6 is enabled, IPv6 traffic needs its own intended firewall policy through the active firewall manager or, where appropriate, ip6tables. Verify both address families; an IPv4 INPUT policy does not cover IPv6.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.