iptables: command not found
This error has two common causes: iptables is not installed, or it is installed but your shell cannot find it. Check which one first.
command -v iptables ls -l /usr/sbin/iptables /sbin/iptables
Both commands print nothing or "No such file": iptables is not installed, go to Fix 1.
The file exists in /usr/sbin or /sbin: it is installed but not in your PATH, go to Fix 2.
Fix 1: install iptables
| System | Command |
|---|---|
| Ubuntu, Debian | sudo apt update && sudo apt install -y iptables |
| RHEL 8+, Rocky, Alma, Fedora | sudo dnf install -y iptables-nft |
| CentOS 7 | sudo yum install -y iptables |
| Alpine | apk add iptables |
| Arch | sudo pacman -S iptables |
Minimal server images, newer Debian releases and most container images do not include iptables. On RHEL-family systems, add iptables-services if you also want to save rules across reboots (see how to save iptables rules).
Fix 2: run it with sudo or the full path
iptables lives in /usr/sbin (or /sbin), a directory reserved for administration tools. On Debian, a normal user or a plain su session often does not have it in PATH. Any of these works:
sudo iptables -L -n sudo /usr/sbin/iptables -L -n su - # note the dash: it loads root's full PATH
Verify the install
sudo iptables --version
The output ends with (nf_tables) or (legacy). Modern distributions ship iptables as a compatibility layer on top of nftables, so both variants work for the usual allow and block rules. Try listing the rules:
sudo iptables -L INPUT -n --line-numbers
Inside a Docker container
Container images are stripped down, so install iptables inside the container first. Then note that changing firewall rules from a container needs extra privileges:
docker run --cap-add=NET_ADMIN -it ubuntu bash
Without NET_ADMIN, iptables installs fine but fails with a permission error when you use it. In most cases it is better to manage firewall rules on the host instead.
Other errors you may hit next
Permission denied (you must be root): add sudo.
Can't initialize iptables table 'filter': the kernel firewall modules are missing or the environment (some containers and VPS types) does not allow iptables. Check sudo modprobe ip_tables or ask your provider.
Rules work but disappear after reboot: see saving iptables rules permanently.
FAQ
Why is iptables missing on a fresh Debian or Ubuntu install?
Minimal and cloud images keep the package list short. Firewall tools are optional, so you install iptables yourself with apt.
Is iptables replaced by nftables?
Most current distributions use nftables in the kernel, and the iptables command is a compatibility wrapper (iptables-nft). Your existing iptables commands still work.
Why does it work with sudo but not without?
The binary is in /usr/sbin, which is often missing from a normal user's PATH. sudo uses a secure PATH that includes it. iptables also needs root to change rules.
Do I need iptables if I use ufw?
ufw is a front end that calls iptables or nftables underneath, so the backend must be present. Installing ufw normally pulls it in.