Iptables: Difference between revisions
From James's Wiki
No edit summary |
No edit summary |
||
Line 27: | Line 27: | ||
sudo iptables-save > iptables.rules | sudo iptables-save > iptables.rules | ||
sudo iptables-restore < iptables.rules | sudo iptables-restore < iptables.rules | ||
check hit conuts for all rules: | |||
sudo iptables -vL --line-numbers | |||
references: | references: | ||
https://www.digitalocean.com/community/tutorials/iptables-essentials-common-firewall-rules-and-commands | https://www.digitalocean.com/community/tutorials/iptables-essentials-common-firewall-rules-and-commands |
Revision as of 21:12, 6 March 2018
to save firewall rules use:
sudo dpkg-reconfigure iptables-persistent
or (stretch):
sudo dpkg-reconfigure iptables-persistent
allow ssh:
sudo iptables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT sudo iptables -A OUTPUT -p tcp --sport 22 -m conntrack --ctstate ESTABLISHED -j ACCEPT
delete by number:
sudo iptables -L --line-numbers sudo iptables -D INPUT 3
set overall policies:
iptables -P INPUT DROP iptables -P FORWARD ACCEPT iptables -P OUTPUT ACCEPT
accept tcp 8080 from local:
sudo iptables -A INPUT -p tcp --dport 8080 -s 192.168.1.0/24 -j ACCEPT
to save rules to text file and restore from said file:
sudo iptables-save > iptables.rules sudo iptables-restore < iptables.rules
check hit conuts for all rules:
sudo iptables -vL --line-numbers
references: