How to Save iptables Rules Permanently
iptables rules live in kernel memory. After a reboot they are gone unless you saved them and something loads them back at boot.
sudo apt install -y iptables-persistent sudo netfilter-persistent save
The rules are written to /etc/iptables/rules.v4 and /etc/iptables/rules.v6 and restored on every boot. Other distributions are covered below.
Ubuntu and Debian: netfilter-persistent
Install the package once. If the installer asks whether to save the current IPv4 and IPv6 rules, answer Yes.
sudo apt update sudo apt install -y iptables-persistent
After every change to your rules, save again:
sudo netfilter-persistent save
To reload the saved file without rebooting, run sudo netfilter-persistent reload.
RHEL, Rocky Linux and AlmaLinux: iptables-services
These systems use firewalld by default. To manage iptables directly, install the service and turn firewalld off so the two do not fight over the rules.
sudo dnf install -y iptables-services sudo systemctl disable --now firewalld sudo systemctl enable --now iptables sudo service iptables save
The rules are saved to /etc/sysconfig/iptables. If you prefer to keep firewalld, use firewall-cmd --permanent instead and skip iptables entirely.
Manual method: iptables-save
You can also dump the rules yourself. Note that a plain sudo iptables-save > file fails, because the redirect runs as your normal user. Use tee:
sudo iptables-save | sudo tee /etc/iptables/rules.v4 sudo ip6tables-save | sudo tee /etc/iptables/rules.v6
To load a saved file back into the running firewall:
sudo iptables-restore < /etc/iptables/rules.v4
Check that it worked
Look at the saved file, then reboot and list the live rules:
sudo cat /etc/iptables/rules.v4 sudo reboot # after logging back in: sudo iptables -L INPUT -n --line-numbers
On RHEL-family systems, read /etc/sysconfig/iptables instead.
Common problems
Rules vanish after reboot. You saved to a file, but nothing loads it. On Ubuntu and Debian make sure iptables-persistent is installed; on RHEL make sure the iptables service is enabled.
Only IPv4 rules survive. IPv6 rules live in a separate file (rules.v6). netfilter-persistent save writes both.
You use Docker. Docker creates its own chains at startup. Saving them and restoring them at boot can leave stale entries, so review the saved file before you rely on it.
Oracle Cloud. New rules must sit above the default REJECT rule before you save. See how to open a port on Oracle Cloud.
FAQ
Where does iptables store saved rules?
iptables itself stores nothing. Debian and Ubuntu keep saved rules in /etc/iptables/rules.v4 and rules.v6, and RHEL-family systems use /etc/sysconfig/iptables.
Is iptables-persistent the same as netfilter-persistent?
On Debian and Ubuntu, iptables-persistent is the package that installs the netfilter-persistent command and its boot-time service. You install one and use the other.
Do I need to save after every rule change?
Yes. The saved file is a snapshot. Rules added afterwards exist only in memory until you run the save command again.
Can I generate the rules first?
Yes. Our iptables generator builds allow and block commands and shows the save step for your system.