Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
iptables-essentials — Iptables Essentials: Common Firewall Rules and Commands. | Kitploit
Tools/GitHubGitHub/trimstray/iptables-essentials
Configuration AuditingNetwork SecurityLearning & EducationCurated Resources
GitHubtrimstray/iptables-essentials

iptables-essentials

Iptables Essentials: Common Firewall Rules and Commands.

View Repository
1.6k289111 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Iptables Essentials: Common Firewall Rules and Commands


Pull Requests MIT License


☑️ TODO

  • Add useful Iptables configuration examples
  • Add useful Kernel Settings (sysctl) configuration
  • Add links to useful external resources
  • Add advanced configuration examples, commands, rules

Table of Contents

  • Tools to help you configure Iptables
  • Manuals/Howtos/Tutorials
  • Useful Kernel Settings (sysctl) configuration
    • rp_filter
    • log_martians
    • send_redirects
    • accept_source_route
    • accept_redirects
    • tcp_syncookies
    • icmp_echo_ignore_broadcasts
    • ip_forward
  • How it works?
  • Iptables Rules
    • Saving Rules
      • Debian Based
      • RedHat Based
    • List out all of the active iptables rules with verbose
    • List out all of the active iptables rules with numeric lines and verbose
    • Print out all of the active iptables rules
    • List Rules as Tables for INPUT chain
    • Print all of the rule specifications in the INPUT chain
    • Show Packet Counts and Aggregate Size
    • To display INPUT or OUTPUT chain rules with numeric lines and verbose
    • Delete Rule by Chain and Number
    • Delete Rule by Specification
    • Flush All Rules, Delete All Chains, and Accept All
    • Flush All Chains
    • Flush a Single Chain
    • Insert Firewall Rules
    • Allow Loopback Connections
    • Allow Established and Related Incoming Connections
    • Allow Established Outgoing Connections
    • Internal to External
    • Drop Invalid Packets
    • Block an IP Address
    • Block and IP Address and Reject
    • Block Connections to a Network Interface
    • Allow All Incoming SSH
    • Allow Incoming SSH from Specific IP address or subnet
    • Allow Outgoing SSH
    • Allow Incoming Rsync from Specific IP Address or Subnet
    • Allow All Incoming HTTP
    • Allow All Incoming HTTPS
    • Allow All Incoming HTTP and HTTPS
    • Allow MySQL from Specific IP Address or Subnet
    • Allow MySQL to Specific Network Interface
    • PostgreSQL from Specific IP Address or Subnet
    • Allow PostgreSQL to Specific Network Interface
    • Block Outgoing SMTP Mail
    • Allow All Incoming SMTP
    • Allow All Incoming IMAP
    • Allow All Incoming IMAPS
    • Allow All Incoming POP3
    • Allow All Incoming POP3S
    • Drop Private Network Address On Public Interface
    • Drop All Outgoing to Facebook Networks
    • Log and Drop Packets
    • Log and Drop Packets with Limited Number of Log Entries
    • Drop or Accept Traffic From Mac Address
    • Block or Allow ICMP Ping Request
    • Specifying Multiple Ports with multiport
    • Load Balancing with random* or nth*
    • Restricting the Number of Connections with limit and iplimit*
    • Maintaining a List of recent Connections to Match Against
    • Matching Against a string* in a Packet's Data Payload
    • Time-based Rules with time*
    • Packet Matching Based on TTL Values
    • Protection against port scanning
    • SSH brute-force protection
    • Syn-flood protection
      • Mitigating SYN Floods With SYNPROXY
    • Block New Packets That Are Not SYN
    • Force Fragments packets check
    • XMAS packets
    • Drop all NULL packets
    • Block Uncommon MSS Values
    • Block Packets With Bogus TCP Flags
    • Block Packets From Private Subnets (Spoofing)
  • Advanced configuration examples
    • Packet handling in Python using NFQUEUE target
      • ACCEPT all packets from specific source on (filter:INPUT) and DROP everything else
      • Write your own port knocking script to secure ssh access

Tools to help you configure Iptables

  :small_orange_diamond: Shorewall - advanced gateway/firewall configuration tool for GNU/Linux.
  :small_orange_diamond: Firewalld - provides a dynamically managed firewall.
  :small_orange_diamond: UFW - default firewall configuration tool for Ubuntu.
  :small_orange_diamond: FireHOL - offer simple and powerful configuration for all Linux firewall and traffic shaping requirements.

Manuals/Howtos/Tutorials

Download Tool