Understanding iptables: Your First Steps to a Linux Firewall
Have you ever thought about how a firewall works, how to set up simple rules, and how to understand iptables?

Hello, I'm Ganesh. I'm working on FreeDevTools online currently building one place for all dev tools, cheat codes, and TLDRs — a free, open-source hub where developers can quickly find and use tools without any hassle of searching all over the internet.
In many cases, a powerful and versatile firewall tool called iptables is used. While its reputation for complexity can be intimidating, understanding its core logic is simpler than you think.
A firewall acts as a security guard for your computer's network traffic. It inspects every data "packet" trying to get in or out and decides what to do with it based on a set of rules you define.
The iptables command is how you configure these rules within the Linux kernel's networking framework, Netfilter. This guide will break down the essential concepts of iptables and walk you through creating your very first firewall rule.
The Three Pillars: Rules, Chains, and Targets
To get started, let's look at the fundamental building blocks of any iptables configuration. Think of it as a security checkpoint at an airport.
Rules: The Instructions
A rule is a single instruction for the firewall. It always consists of two parts:
A Matcher: This is the "if" part of the instruction. It specifies the criteria a data packet must meet. For example, "if the packet is from the IP address
192.168.1.100" or "if the packet is trying to connect to port22(SSH)."A Target: This is the "then" part of the instruction. It tells the firewall what action to take if a packet meets the criteria. For example, "then allow it" or "then block it."
So, a complete rule is a simple statement: "If a packet comes from 192.168.1.100, then block it."
Chains: The Checklists
A chain is an ordered list of rules. When a packet arrives, it's checked against the rules in a chain, one by one, from top to bottom, like a security guard going through a checklist.
Does the packet match Rule #1?
Yes: The action in Rule #1's target is taken, and the process stops. The packet isn't checked against any other rules in this chain.
No: The firewall moves on to check Rule #2.
This continues until a rule is matched. There are three essential built-in chains you'll use constantly:
INPUT: For packets coming into your machine.OUTPUT: For packets generated by and going out from your machine.FORWARD: For packets being routed through your machine (for example, if it's acting as a router).
Targets: The Actions
A target is the final action specified in a rule. The three most common targets are:
ACCEPT: Let the packet through. The security guard waves it on.DROP: Silently discard the packet. The sender receives no reply and doesn't know if the packet ever arrived. This is like the guard simply ignoring the packet.REJECT: Block the packet but send an error message back (e.g., "connection refused"). This is like the guard explicitly telling the sender, "You are not allowed here."
In short, Rules are individual instructions containing a matcher and a target. These rules are placed in order inside a chain.
Understanding Tables
Now that we have rules organized into chains, what's the next level? That would be tables.
A table is a collection of chains that all serve a single, specific purpose. Think of it as having different instruction manuals for your security guard—one for general security checks, another for changing package addresses, and a third for special handling.
iptables has four main tables, but you'll primarily work with the first two.
The
filterTable: This is the default and most commonly used table. Its job is simple: to filter packets. This is where yourACCEPT,DROP, andREJECTrules live. It contains theINPUT,OUTPUT, andFORWARDchains.The
natTable: This table, standing for Network Address Translation, is responsible for changing the source or destination IP address of packets. It's essential when using your machine as a router to share an internet connection.The
mangleTable: This is for advanced packet alteration, like modifying specific data fields to prioritize certain types of traffic.The
rawTable: A highly specialized table used to exempt certain packets from connection tracking.
For now, let’s just focus on the filter table, as it's where you'll do 90% of your firewall work. The hierarchy is simple: Tables contain Chains, and Chains contain Rules.
Blocking a Malicious IP Address using iptables
Theory is great, but let's put it into practice. Imagine a specific IP address, 198.51.100.10, is causing problems, and you want to block all incoming traffic from it.
We need to create a rule that says: "If a packet is from 198.51.100.10, then DROP it."
To build this command, we need to specify three things: the chain, the matcher, and the target.
The Chain: Since we're blocking traffic coming in, we'll add the rule to the
INPUTchain. The command flag for this is-A INPUT(Afor "append").The Matcher: We want to match packets from a specific source IP. The flag for the source is
-s. So, the matcher is-s 198.51.100.10.The Target: We want to
DROPthe packet. The flag to specify the target is-j(jfor "jump"). So, the target is-j DROP.
Putting it all together, the final command is:
sudo iptables -A INPUT -s 198.51.100.10 -j DROP
Did It Work? Viewing Your Rules
Now that you've added a rule, how do you see it? The -L flag is for Listing rules. To see all rules in the INPUT chain, you would run:
sudo iptables -L INPUT
However, we can make this output much more useful with a few extra flags:
-v(verbose): Shows more detail, like packet and byte counters.-n(numeric): Shows IP addresses and port numbers numerically instead of trying to resolve their names. This is faster and clearer.--line-numbers: Shows the number of each rule in the chain, which is essential for managing them later.
Combining these gives you the command you'll likely use most often to check your configuration:
sudo iptables -L INPUT -vn --line-numbers
We've now covered how to add and view a rule. The logical next step, of course, is learning how to remove one.
Deleting a Rule
Just like adding a rule, there are a couple of ways to delete one. The easiest and most common method relies on the line numbers we just learned about.
Method 1: Deleting by Line Number (The Easy Way)
This is why the --line-numbers flag is so useful. Once you've listed your rules and identified the number of the one you want to remove, you can delete it with the -D (delete) flag.
First, list the rules to find the one you want to delete:
sudo iptables -L INPUT --line-numbers
Let's say the rule we created earlier (-s 198.51.100.10 -j DROP) is at line number 1. To remove it, you simply tell iptables to delete line 1 from the INPUT chain:
sudo iptables -D INPUT 1
The firewall will immediately remove that rule from the chain, and traffic from that IP will no longer be blocked.
Method 2: Deleting by Rule Specification
You can also delete a rule by specifying the exact same rule, but replacing the -A (append) flag with -D (delete).
For our example, the command would be:
sudo iptables -D INPUT -s 198.51.100.10 -j DROP
This method is useful if you know the exact rule you want to remove without having to list them first. However, it's more typing and prone to errors. Most people find deleting by line number to be quicker and safer.
With these three operations—Appending, Listing, and Deleting—you now have the fundamental skills to manage a basic iptables firewall.
Keep in mind that these rules are not permanent; they will be lost when the system reboots. The next step is learning how to save your ruleset so it reloads automatically.
By default, any rules you create iptables are temporary and will disappear when you restart your machine. Here’s how you make them permanent.
Making Your Rules Stick
The most common and recommended way to save your firewall rules is by using a helper package that handles the process for you. The package name differs depending on your Linux distribution.
On Debian/Ubuntu Systems
The package you'll want is iptables-persistent.
Install the package:
sudo apt update sudo apt install iptables-persistentSave during installation: During the installation process, a prompt will appear asking if you want to save your current IPv4 and IPv6 rules. Select
<Yes>for both.Saving rules later: If you change your rules in the future and want to save the new configuration, simply run this command:
Bash
sudo netfilter-persistent saveThis command saves your current
iptables(IPv4) andip6tables(IPv6) rules to/etc/iptables/rules.v4and/etc/iptables/rules.v6respectively. The service automatically reloads these rules every time the system boots up.
By using these packages, you ensure that your carefully crafted firewall ruleset is always active, protecting your system from the moment it starts up.
I’ve been building for FreeDevTools.
A collection of UI/UX-focused tools crafted to simplify workflows, save time, and reduce friction in searching tools/materials.
Any feedback or contributions are welcome!
It’s online, open-source, and ready for anyone to use.
👉 Check it out: FreeDevTools
⭐ Star it on GitHub: freedevtools





