iptables Filter Table: Packet Filtering Rules

The filter table in iptables is the default table and is primarily used for packet filtering. This table allows you to make decisions on whether to ACCEPT, DROP, or REJECT packets based on various criteria, thereby controlling which traffic is allowed to enter, leave, or pass through your system.

1. Common iptables Flags and Parameters

Rule Management Actions

These flags determine how a rule is added or removed from a chain.

  • -I <chain> [<rulenum>]: Insert a rule into the specified chain at a given rule number (defaults to the beginning if no number is given).
  • -A <chain>: Append a rule to the end of the specified chain.
  • -D <chain> [<rulenum>] / -D <chain> <rule-specification>: Delete a rule by its number or by matching its full specification.

Matching Parameters

These flags define criteria for matching packets.

  • -s <source>: Matches packets originating from the specified source IP address or network (e.g., 192.168.1.0/24).
  • -d <destination>: Matches packets destined for the specified destination IP address or network.
  • -p <protocol>: Matches packets of a specific protocol (e.g., tcp, udp, icmp).
  • --dport <port>: Matches packets with a specific destination port (used with -p tcp or -p udp).
  • --sport <port>: Matches packets with a specific source port (used with -p tcp or -p udp).
  • -i <input_interface>: Matches packets entering through the specified network interface (e.g., eth0).
  • -o <output_interface>: Matches packets exiting through the specified network interface.

Target/Action

  • -j <target>: Specifies the target or action to perform if the packet matches the rule. Common targets include ACCEPT, DROP, REJECT, LOG, or jumping to a user-defined chain.

Modules (-m)

iptables uses modules to extend its functionality, providing additional matching capabilities.

  • -m <module_name>: Loads a specific iptables extension module.
  • --src-range <ip_range> (with -m iprange): Matches a range of source IP addresses.

2. Adding Filter Rules

Basic Drop Rules

These examples demonstrate how to drop incoming traffic based on source IP and port.

# Deny all incoming traffic from a specific subnet
iptables -I INPUT -s 10.0.0.0/24 -j DROP
 
# Deny incoming TCP traffic from a specific subnet to port 80
iptables -I INPUT -s 10.0.0.0/24 -p tcp --dport 80 -j DROP

Adding Rules with Comments

It’s good practice to add comments to your iptables rules for clarity and maintainability.

# Add a rule to the INPUT chain with a descriptive comment
iptables -I INPUT -s 10.0.0.0/24 -j DROP -m comment --comment "deny internal network access"

Connection Tracking (-m conntrack)

The conntrack module is vital for stateful firewalling. It allows iptables to keep track of network connections and apply rules based on their state.

# Allow established and related connections
# This is crucial to maintain existing connections (e.g., an active SSH session)
# even if new incoming connections are blocked later in the chain.
iptables -A INPUT -j ACCEPT -m conntrack --ctstate ESTABLISHED,RELATED
iptables -A OUTPUT -j ACCEPT -m conntrack --ctstate ESTABLISHED,RELATED
  • --ctstate ESTABLISHED,RELATED: Matches packets that belong to an existing connection (ESTABLISHED) or are new connections related to an existing one (RELATED, e.g., FTP data channels).

3. Deleting Filter Rules

Rules can be deleted either by their exact specification or by their line number within a chain. Deleting by line number is often more precise.

List Rules with Line Numbers

First, display the rules in a chain with their corresponding numbers.

iptables -L INPUT --line-numbers

Delete a Rule by Line Number

# Delete the rule at line number 1 in the INPUT chain
iptables -D INPUT 1

Warning: Always exercise caution when modifying iptables rules. Incorrect rules can lead to network connectivity issues or even lock you out of your system. It is advisable to test rules in a non-critical environment and have a recovery plan.