Code-Memo

Firewalls (iptables, nftables)

Overview

Linux firewalls filter packets using netfilter. Frontends:

Quick status

iptables (legacy view):

sudo iptables -L -n -v
sudo iptables -S

nftables:

sudo nft list ruleset

Common patterns

Allow SSH (example)

iptables:

sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT

nft (conceptual):

sudo nft add rule inet filter input tcp dport 22 accept

Persist rules

Depends on distro/tooling:

Tips