iptables Filter Table: Packet Filtering Rules
The filter table in iptables is the default table and is primarily used for packet filtering. This table allows you to make decisions on whether to ACCEPT, DROP, or REJECT packets based on various criteria, thereby controlling which traffic is allowed to enter, leave, or pass through your system.
1. Common iptables Flags and Parameters
Rule Management Actions
These flags determine how a rule is added or removed from a chain.
-I <chain> [<rulenum>]: Insert a rule into the specified chain at a given rule number (defaults to the beginning if no number is given).-A <chain>: Append a rule to the end of the specified chain.-D <chain> [<rulenum>]/-D <chain> <rule-specification>: Delete a rule by its number or by matching its full specification.
Matching Parameters
These flags define criteria for matching packets.
-s <source>: Matches packets originating from the specified source IP address or network (e.g.,192.168.1.0/24).-d <destination>: Matches packets destined for the specified destination IP address or network.-p <protocol>: Matches packets of a specific protocol (e.g.,tcp,udp,icmp).--dport <port>: Matches packets with a specific destination port (used with-p tcpor-p udp).--sport <port>: Matches packets with a specific source port (used with-p tcpor-p udp).-i <input_interface>: Matches packets entering through the specified network interface (e.g.,eth0).-o <output_interface>: Matches packets exiting through the specified network interface.
Target/Action
-j <target>: Specifies the target or action to perform if the packet matches the rule. Common targets includeACCEPT,DROP,REJECT,LOG, or jumping to a user-defined chain.
Modules (-m)
iptables uses modules to extend its functionality, providing additional matching capabilities.
-m <module_name>: Loads a specificiptablesextension module.--src-range <ip_range>(with-m iprange): Matches a range of source IP addresses.
2. Adding Filter Rules
Basic Drop Rules
These examples demonstrate how to drop incoming traffic based on source IP and port.
# Deny all incoming traffic from a specific subnet
iptables -I INPUT -s 10.0.0.0/24 -j DROP
# Deny incoming TCP traffic from a specific subnet to port 80
iptables -I INPUT -s 10.0.0.0/24 -p tcp --dport 80 -j DROPAdding Rules with Comments
It’s good practice to add comments to your iptables rules for clarity and maintainability.
# Add a rule to the INPUT chain with a descriptive comment
iptables -I INPUT -s 10.0.0.0/24 -j DROP -m comment --comment "deny internal network access"Connection Tracking (-m conntrack)
The conntrack module is vital for stateful firewalling. It allows iptables to keep track of network connections and apply rules based on their state.
# Allow established and related connections
# This is crucial to maintain existing connections (e.g., an active SSH session)
# even if new incoming connections are blocked later in the chain.
iptables -A INPUT -j ACCEPT -m conntrack --ctstate ESTABLISHED,RELATED
iptables -A OUTPUT -j ACCEPT -m conntrack --ctstate ESTABLISHED,RELATED--ctstate ESTABLISHED,RELATED: Matches packets that belong to an existing connection (ESTABLISHED) or are new connections related to an existing one (RELATED, e.g., FTP data channels).
3. Deleting Filter Rules
Rules can be deleted either by their exact specification or by their line number within a chain. Deleting by line number is often more precise.
List Rules with Line Numbers
First, display the rules in a chain with their corresponding numbers.
iptables -L INPUT --line-numbersDelete a Rule by Line Number
# Delete the rule at line number 1 in the INPUT chain
iptables -D INPUT 1Warning: Always exercise caution when modifying iptables rules. Incorrect rules can lead to network connectivity issues or even lock you out of your system. It is advisable to test rules in a non-critical environment and have a recovery plan.