iptables-persistent: Making iptables Rules Permanent
By default, iptables rules are volatile and are lost upon system reboot. To make your firewall rules persistent across reboots, you need a mechanism to save and restore them. On Debian-based systems (like Ubuntu), the iptables-persistent package handles this process automatically.
1. Install iptables-persistent
This package provides scripts that save your current iptables rules to a file and restore them at boot time.
sudo apt install iptables-persistentDuring installation, you will be prompted to save your current IPv4 and IPv6 iptables rules. Select “Yes” to save them.
2. Manually Save Current iptables Rules
If you make changes to your iptables rules after the initial installation of iptables-persistent, you must explicitly save them for the changes to persist across reboots.
# Save IPv4 rules
sudo /sbin/iptables-save > /etc/iptables/rules.v4
# Save IPv6 rules (if applicable)
sudo /sbin/ip6tables-save > /etc/iptables/rules.v6These commands directly write the current rule set to the specified files, which iptables-persistent will then load on the next boot.
3. Verify Saved iptables Rules
You can inspect the content of the saved rule files to confirm that your desired rules have been written correctly.
# Check saved IPv4 rules
cat /etc/iptables/rules.v4
# Check saved IPv6 rules
cat /etc/iptables/rules.v6This allows you to review the rules that will be applied automatically at system startup.