← Home  |  PacketUtils

iptables Command Generator

Choose allow or block, enter a port, and copy the command. Optionally limit it to one IP or subnet. ufw and firewalld versions are generated too.

iptables

Make it survive a reboot

Same rule in other firewalls

ufw

firewalld

Before you run it

Order matters. iptables checks rules from top to bottom and stops at the first match. If your chain already ends with a REJECT or DROP rule, a rule appended with -A is never reached. Check with sudo iptables -L INPUT -n --line-numbers and use insert (-I) if needed. Many cloud images, including Ubuntu on Oracle Cloud, ship with a catch-all REJECT rule near the end of INPUT.

Do not lock yourself out. Before blocking anything, make sure an allow rule for SSH (port 22, or your custom port) sits above it.

Cloud firewalls are separate. On AWS, Azure, GCP and Oracle Cloud, the provider's security group or security list must also allow the port.

FAQ

What is the difference between DROP and REJECT?

DROP discards the packet without a reply, so the sender waits until it times out. REJECT sends back an error immediately. DROP reveals less; REJECT gives faster feedback.

How do I allow a port for only one IP address?

Fill in the IP or subnet field. The generator adds -s for incoming rules, so only that source can reach the port. Add a separate block rule below it if you also want everyone else denied.

Why did my rule disappear after a reboot?

iptables rules live in memory. Save them with netfilter-persistent on Debian and Ubuntu, or service iptables save with iptables-services on RHEL-family systems.

How do I open several ports at once?

Separate them with commas, for example 80,443. The generator uses the multiport module. Use a colon for a range, such as 8000:8100.