{"id":26235,"date":"2023-02-22T15:22:06","date_gmt":"2023-02-22T15:22:06","guid":{"rendered":"http:\/\/localhost\/helpold\/?p=26235"},"modified":"2025-01-02T13:26:28","modified_gmt":"2025-01-02T09:56:28","slug":"install-configure-iptables","status":"publish","type":"post","link":"https:\/\/www.arvancloud.ir\/help\/en\/install-configure-iptables\/","title":{"rendered":"How To Install And Configure Iptables Firewall On Ubuntu?"},"content":{"rendered":"<p>Throughout this guide, we will break down the Iptables tutorial into three steps. First, we will talk about how to install the firewall in Ubuntu. The second step will discuss how to define the firewall rules and eventually we will make the iptables changes persistent in the instance.<\/p>\n<h2>Step One: Installing Iptables<\/h2>\n<p>Iptables is installed by default on most Linux distributions. But if you don&#8217;t already have it on your Ubuntu\/Debian system by default, then follow these steps:<\/p>\n<p>After connecting to your instance, run the following commands one by one:<\/p>\n<pre><code>sudo apt-get update<\/code><\/pre>\n<pre><code>sudo apt-get install iptables<\/code><\/pre>\n<p>To check the status of your current iptables configuration, use the following command:<\/p>\n<pre><code>sudo iptables -L -v<\/code><\/pre>\n<p>In this command, the L- flag is used to list all the rules, and the v- flag to display the information in a more detailed format. You can see an example of the output below:<\/p>\n<pre><code>Chain INPUT (policy ACCEPT 0 packets, 0 bytes)\r\n pkts bytes target     prot opt in  out  source  destination\r\n\r\nChain FORWARD (policy ACCEPT 0 packets, 0 bytes)\r\n pkts bytes target     prot opt in  out  source  destination\r\n\r\nChain OUTPUT (policy ACCEPT 0 packets, 0 bytes)\r\n pkts bytes target     prot opt in  out  source  destination\r\n<\/code><\/pre>\n<p>You have now successfully installed the iptables firewall. At this point, all of the chains are set to ACCEPT and they have no rules. This is not safe because any packet can arrive without being filtered.<\/p>\n<h2>Step Two: Defining Chain Rules<\/h2>\n<p>To define a rule is to add it to the end of the chain. For this purpose, you must enter the -A (append) flag right after the iptables command, for example:<\/p>\n<pre><code>sudo iptables -A<\/code><\/pre>\n<p>You can then combine the command with other options, such as:<\/p>\n<ul>\n<li>i (interface) &#8211; The network interface in which traffic should be filtered, for example, eth0, lo, ppp0, etc.<\/li>\n<li>p (protocol) &#8211; The network protocol where the filtering operation is being done. This can be tcp, udp, udplite, icmp, sctp, icmpv6, and so on. You can also type all to select any protocol.<\/li>\n<li>s (source) &#8211; The address from which the traffic is originating. You may enter a hostname or an IP address.<\/li>\n<li>dport (destination port) &#8211; The destination port number of a protocol, for example, 22 (SSH), 443 (https), etc.<\/li>\n<li>J (target) &#8211; The target name (ACCEPT, DROP, RETURN). You must enter this whenever you create a new rule.<\/li>\n<\/ul>\n<p>When you want to use all of them, you need to type the command in the following order:<\/p>\n<pre><code>sudo iptables -A &lt;chain&gt; -i &lt;interface&gt; -sudo iptables -A &lt;chain&gt; -i &lt;interface&gt; -p &lt;protocol (tcp\/udp) &gt; -s &lt;source&gt; --dport &lt;port no.&gt;\u00a0 -j &lt;target&gt;<\/code><\/pre>\n<p>Having now learned the basics of Iptables commands, we can now configure the firewall for greater instance security.<\/p>\n<h3>Step Three: Making the Changes Persistent<\/h3>\n<p>The Iptables rules that we create are stored in memory. As a result, we will have to define them again after a reboot. To make these changes permanent following a restart of the instance, you could use the following command:<\/p>\n<pre><code>sudo \/sbin\/iptables-save<\/code><\/pre>\n<p>With this command, the current rules will be stored in the system configuration file, and this file will be used to reconfigure the tables every time the server is rebooted.<\/p>\n<p>Keep in mind that you must run this command every time you change the rules. If you want to disable iptables, for example, you have to run these two lines:<\/p>\n<pre><code>sudo iptables -F<\/code><\/pre>\n<pre><code>sudo \/sbin\/iptables-save<\/code><\/pre>\n<p>You will get the following output:<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-full wp-image-26236 aligncenter\" src=\"https:\/\/www.arvancloud.ir\/help\/wp-content\/uploads\/2024\/12\/\u0634\u06cc\u0648\u0647-\u0646\u0635\u0628-\u0648-\u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc-\u0641\u0627\u06cc\u0631\u0648\u0627\u0644-iptables-\u0631\u0648\u06cc-ubuntu-5939635221788_picture1-2-1.png\" alt=\"\" width=\"653\" height=\"268\" \/><\/p>\n<p>Iptables provides a powerful firewall for you to protect your Linux servers. We talked about how to install and use this tool during this tutorial. If you want to learn more about the rules and examples of this firewall, feel free to refer to the article &#8220;Iptables Common Rules and Commands.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Throughout this guide, we will break down the Iptables tutorial into three steps. First, we will talk about how to install the firewall in Ubuntu. The second step will discuss how to define the firewall rules and eventually we will make the iptables changes persistent in the instance. Step One: Installing Iptables Iptables is installed [&hellip;]<\/p>\n","protected":false},"author":79,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"r1_post_views_count":"1053","feedback_yes":"1","feedback_no":"1","ads_id_sidebar":"","ads_id_content":"","footnotes":""},"categories":[245,287],"tags":[],"class_list":["post-26235","post","type-post","status-publish","format-standard","hentry","category-cloud-server","category-server-security"],"lang":"en","translations":{"en":26235},"pll_sync_post":[],"_links":{"self":[{"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/posts\/26235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/users\/79"}],"replies":[{"embeddable":true,"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/comments?post=26235"}],"version-history":[{"count":5,"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/posts\/26235\/revisions"}],"predecessor-version":[{"id":28281,"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/posts\/26235\/revisions\/28281"}],"wp:attachment":[{"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/media?parent=26235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/categories?post=26235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.arvancloud.ir\/help\/wp-json\/wp\/v2\/tags?post=26235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}