← Home  |  PacketUtils

How to Save iptables Rules Permanently

iptables rules live in kernel memory. After a reboot they are gone unless you saved them and something loads them back at boot.

Quick answer for Ubuntu and Debian
sudo apt install -y iptables-persistent
sudo netfilter-persistent save

The rules are written to /etc/iptables/rules.v4 and /etc/iptables/rules.v6 and restored on every boot. Other distributions are covered below.

Test before you save. A saved rule that blocks SSH will still be there after a reboot, and you will be locked out for good. Keep a second SSH session open, confirm the new rules work, then save.

Ubuntu and Debian: netfilter-persistent

Install the package once. If the installer asks whether to save the current IPv4 and IPv6 rules, answer Yes.

sudo apt update
sudo apt install -y iptables-persistent

After every change to your rules, save again:

sudo netfilter-persistent save

To reload the saved file without rebooting, run sudo netfilter-persistent reload.

RHEL, Rocky Linux and AlmaLinux: iptables-services

These systems use firewalld by default. To manage iptables directly, install the service and turn firewalld off so the two do not fight over the rules.

sudo dnf install -y iptables-services
sudo systemctl disable --now firewalld
sudo systemctl enable --now iptables
sudo service iptables save

The rules are saved to /etc/sysconfig/iptables. If you prefer to keep firewalld, use firewall-cmd --permanent instead and skip iptables entirely.

Manual method: iptables-save

You can also dump the rules yourself. Note that a plain sudo iptables-save > file fails, because the redirect runs as your normal user. Use tee:

sudo iptables-save | sudo tee /etc/iptables/rules.v4
sudo ip6tables-save | sudo tee /etc/iptables/rules.v6

To load a saved file back into the running firewall:

sudo iptables-restore < /etc/iptables/rules.v4

Check that it worked

Look at the saved file, then reboot and list the live rules:

sudo cat /etc/iptables/rules.v4
sudo reboot
# after logging back in:
sudo iptables -L INPUT -n --line-numbers

On RHEL-family systems, read /etc/sysconfig/iptables instead.

Common problems

Rules vanish after reboot. You saved to a file, but nothing loads it. On Ubuntu and Debian make sure iptables-persistent is installed; on RHEL make sure the iptables service is enabled.
Only IPv4 rules survive. IPv6 rules live in a separate file (rules.v6). netfilter-persistent save writes both.
You use Docker. Docker creates its own chains at startup. Saving them and restoring them at boot can leave stale entries, so review the saved file before you rely on it.
Oracle Cloud. New rules must sit above the default REJECT rule before you save. See how to open a port on Oracle Cloud.

FAQ

Where does iptables store saved rules?

iptables itself stores nothing. Debian and Ubuntu keep saved rules in /etc/iptables/rules.v4 and rules.v6, and RHEL-family systems use /etc/sysconfig/iptables.

Is iptables-persistent the same as netfilter-persistent?

On Debian and Ubuntu, iptables-persistent is the package that installs the netfilter-persistent command and its boot-time service. You install one and use the other.

Do I need to save after every rule change?

Yes. The saved file is a snapshot. Rules added afterwards exist only in memory until you run the save command again.

Can I generate the rules first?

Yes. Our iptables generator builds allow and block commands and shows the save step for your system.