Security

iptables Rule Generator

Build an iptables ruleset from a list of allowed services and sources, with stateful connection tracking, rate limiting, logging and a safe default deny policy.

Last reviewed by the Radiatus Cloud team

Ruleset appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Order and default policy are the whole design

iptables evaluates rules in a chain from top to bottom and stops at the first match. That makes ordering load bearing in a way that trips up almost everyone: a permissive rule placed above a restrictive one makes the restriction unreachable. The other half of the design is the default policy at the end of the chain. A firewall with an ACCEPT policy and a list of DROP rules blocks only what you thought of; one with a DROP policy and a list of ACCEPT rules blocks everything you did not.

Connection tracking does most of the work

A single rule accepting ESTABLISHED and RELATED connections at the top of the INPUT chain handles all return traffic for connections your host initiated, which removes the need for the outbound response rules that older firewall configurations were full of. Placing it first also makes the firewall faster, since the overwhelming majority of packets match there and never traverse the rest of the chain.

The rule that locks you out

Setting a DROP policy on INPUT over an SSH session, before adding the rule that permits SSH, disconnects you immediately with no way back except console access. The generated ruleset here places the loopback and established rules first, adds the management access rule before the policy change, and includes a commented rollback timer. Applying a firewall change with a scheduled automatic revert is the standard practice for remote work and it costs nothing.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Should I use iptables or nftables?

nftables is the successor and is the default on current Debian, RHEL and Fedora, with iptables typically present as a compatibility shim. New work should target nftables; iptables syntax remains useful for existing systems and for the enormous body of documentation written against it. Both are generated here.

Why must the established rule come first?

Because it matches the majority of packets, and matching early avoids traversing the rest of the chain. It also ensures return traffic for connections your host started is accepted regardless of what the service specific rules below say.

How do I avoid locking myself out?

Add the management access rule before changing the policy to DROP, and schedule an automatic revert before applying anything remotely. A commented rollback command is included in the output. Console or out of band access is the only recovery if you skip this.

Do these rules survive a reboot?

No. iptables rules live in memory. Persist them with iptables-save and a distribution mechanism such as iptables-persistent on Debian or by writing the nftables ruleset to /etc/nftables.conf and enabling the service.

Does this cover IPv6?

Rules generated for iptables apply to IPv4 only; the ip6tables equivalents are emitted alongside. A host reachable over IPv6 with no ip6tables rules is unfiltered on that protocol, which is a very common oversight.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Add the services you need to allow, then copy the generated ruleset or the nftables equivalent.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.