iptables Administration: Global Commands
This document covers essential administrative commands for managing iptables firewall rulesets. These commands allow you to view existing rules, set default policies, save/restore configurations for persistence, and clear all rules.
1. Viewing iptables Rules
It’s crucial to be able to inspect your current iptables configuration.
List Rules in the filter Table (Default)
The filter table is the default, so -t filter is optional.
# Basic list of rules in the filter table
iptables -L
# Detailed list: numerical IPs/ports, verbose output, with line numbers
iptables -L -n -v --line-numbers-L: List all rules in all chains.-n: Numeric output (prevents DNS lookups, making it faster).-v: Verbose output (shows interface names, rule options, packet/byte counters).--line-numbers: Displays rule numbers, useful for precise deletion.
List Rules in the nat Table
To inspect Network Address Translation (NAT) rules.
# Basic list of rules in the nat table
iptables -t nat -L
# Detailed list: numerical IPs/ports, verbose output, with line numbers
iptables -t nat -L -n -v --line-numbers-t nat: Specifies thenattable.
2. Managing Default Policies
The default policy for a chain (INPUT, FORWARD, OUTPUT) defines the action taken for packets that do not match any explicit rule in that chain. Setting DROP as the default is a security best practice, but requires all desired traffic to be explicitly allowed.
# Set the default policy for the INPUT chain to ACCEPT (use with caution)
iptables --policy INPUT ACCEPT
# To set a more secure default (e.g., DROP), you must ensure critical services
# (like SSH) are explicitly allowed first. Example:
# iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
# iptables -A INPUT -i lo -j ACCEPT
# iptables -A INPUT -p tcp --dport 22 -j ACCEPT
# iptables -P INPUT DROP--policy <chain> <target>: Sets the default target for the specified chain.
3. Saving and Restoring Rules (Persistence)
iptables rules are volatile; they are lost on system reboot unless explicitly saved.
Saving Current Rules
On Debian-based systems (like Ubuntu), you typically use iptables-save.
sudo /sbin/iptables-save > /etc/iptables/rules.v4
# For IPv6 rules:
sudo /sbin/ip6tables-save > /etc/iptables/rules.v6This saves the current rules to a file that can be restored on boot (often via the iptables-persistent package).
Restoring Rules
To load rules from a saved file:
sudo /sbin/iptables-restore < /etc/iptables/rules.v44. Clearing All Rules
To quickly remove all rules from all chains in all tables. This is often used when starting a fresh configuration.
# Clear all rules from the filter table (and all other tables if not specified)
iptables -F
# Clear rules from a specific table, e.g., nat table
iptables -t nat -F
# Delete all non-default (user-defined) chains
iptables -X
# Zero all packet and byte counters
iptables -Z-F: Flushes (deletes) all rules.
5. Deleting Specific Rules
For detailed instructions on deleting specific rules by number or specification, refer to the Filter Table Rules document.
# Example: List rules with line numbers
iptables -L INPUT --line-numbers
# Example: Delete rule at line 2 in INPUT chain
iptables -D INPUT 2Warning: Always exercise caution when managing iptables. Incorrect commands can disrupt network connectivity, lock you out of your system, or expose services to unauthorized access. Ensure you have a recovery plan before making significant changes.