iptables / Firewall Keyboard Shortcuts & Commands (37)
Complete collection of 37 iptables / Firewall keyboard shortcuts and commands. Browse all shortcuts organized by category with our interactive search tool.
This page is deliberately short: it holds the handful of iptables and ufw commands that cover most host-firewall work on a Linux server, not the full rule language. iptables is the classic interface, still present on every distribution even where nftables runs underneath; ufw is Ubuntu's friendlier front end. The notes explain the two things that bite everyone — rule order and persistence.
Related Shortcut Pages
Search all iptables / Firewall shortcuts interactively with real-time filtering
Open Interactive Shortcut FinderCommands (15)
| Shortcut | Action | What it does |
|---|---|---|
| iptables -t (--table) table | Specify the packet matching table the command operates on | The tables are filter (default), nat, mangle, raw and security. If the kernel is configured with automatic module loading, the module for that table is loaded when needed. |
| iptables -A (--append) chain rule-specification | Append one or more rules to the end of the selected chain. | Append one or more rules to the end of the selected chain. When the source and/or destination names resolve to more than one address, a rule will be added for each possible address combination. |
| iptables -C (--check) chain rule-specification | Check whether a rule matching the specification does exist in the selected chain. | Check whether a rule matching the specification does exist in the selected chain. |
| iptables -D (--delete) chain rule-specification | Delete one or more rules from the selected chain. | Delete one or more rules from the selected chain. There are two versions of this command: the rule can be specified as a number in the chain (starting at 1 for the first rule) or a rule to match. |
| iptables -I (--insert) chain [rulenum] rule-specification | Insert one or more rules in the selected chain as the given rule number. | Insert one or more rules in the selected chain as the given rule number. So, if the rule number is 1, the rule or rules are inserted at the head of the chain. This is also the default if no rule number is specified. |
| iptables -R (--replace) chain rulenum rule-specification | Replace a rule in the selected chain. | Replace a rule in the selected chain. If the source and/or destination names resolve to multiple addresses, the command will fail. Rules are numbered starting at 1. |
| iptables -L (--list) [chain] | List all rules in the selected chain. | List all rules in the selected chain. If no chain is selected, all chains are listed. |
| iptables -S (--list-rules) [chain] | Print all rules in the selected chain. | Print all rules in the selected chain. If no chain is selected, all chains are printed like iptables-save. Like every other iptables command, it applies to the specified table (filter is the default). |
| iptables -F (--flush) [chain] | Flush the selected chain (all the chains in the table if none is given). | Flush the selected chain (all the chains in the table if none is given). This is equivalent to deleting all the rules one by one. |
| iptables -Z (--zero) [chain [rulenum]] | Zero the packet and byte counters in all chains, or only the given chain, or only the given rule in a chain. | Zero the packet and byte counters in all chains, or only the given chain, or only the given rule in a chain. It is legal to specify the -L, --list (list) option as well, to see the counters immediately before they are cleared. |
| iptables -N (--new-chain) chain | Create a new user-defined chain by the given name. | Create a new user-defined chain by the given name. There must be no target of that name already. |
| iptables -X (--delete-chain) [chain] | Delete the chain specified. | Delete the chain specified. There must be no references to the chain. If there are, you must delete or replace the referring rules before the chain can be deleted. The chain must be empty, i.e. not contain any rules. |
| iptables -P (--policy) chain target | Set the policy for the built-in (non-user-defined) chain to the given target. | Set the policy for the built-in (non-user-defined) chain to the given target. The policy target must be either ACCEPT or DROP. |
| iptables -E (--rename-chain) old-chain new-chain | Rename the user specified chain to the user supplied name. | Rename the user specified chain to the user supplied name. This is cosmetic, and has no effect on the structure of the table. |
| iptables -h | Help | Give a (currently very brief) description of the command syntax. |
Rule parameters (12)
| Shortcut | Action | What it does |
|---|---|---|
| -4 (--ipv4) | IPv4 rule marker (no effect in iptables itself) | This option has no effect in iptables and iptables-restore. If a rule using the -4 option is inserted with (and only with) ip6tables-restore, it will be silently ignored. Any other uses will throw an error. |
| -6 (--ipv6) | IPv6 rule marker; such rules are ignored by iptables-restore | If a rule using the -6 option is inserted with (and only with) iptables-restore, it will be silently ignored. Any other uses will throw an error. |
| -p (--protocol) protocol | The protocol of the rule or of the packet to check. | The protocol of the rule or of the packet to check. |
| -s (--source) address[/mask][,...] | Source specification. | Source specification. Address can be either a network name, a hostname, a network IP address (with /mask), or a plain IP address. Hostnames will be resolved once only, before the rule is submitted to the kernel. |
| -d (--destination) address[/mask][,...] | Destination specification. | Destination specification. See the description of the -s (source) flag for a detailed description of the syntax. The flag --dst is an alias for this option. |
| -m (--match) match | Specifies a match to use, that is, an extension module that tests for a specific property. | Specifies a match to use, that is, an extension module that tests for a specific property. The set of matches make up the condition under which a target is invoked. |
| -j (--jump) target | This specifies the target of the rule; i.e., what to do if the packet matches it. | This specifies the target of the rule; i.e., what to do if the packet matches it. |
| -g (--goto) chain | This specifies that the processing should continue in a user specified chain. | This specifies that the processing should continue in a user specified chain. Unlike with the --jump option, RETURN will not continue processing in this chain but instead in the chain that called us via --jump. |
| -i (--in-interface) name | Name of an interface via which a packet was received (only for packets entering the INPUT, FORWARD and... | Name of an interface via which a packet was received (only for packets entering the INPUT, FORWARD and PREROUTING chains). When the "!" argument is used before the interface name, the sense is inverted. |
| -o (--out-interface) name | Name of an interface via which a packet is going to be sent (for packets entering the FORWARD, OUTPUT and... | Name of an interface via which a packet is going to be sent (for packets entering the FORWARD, OUTPUT and POSTROUTING chains). When the "!" argument is used before the interface name, the sense is inverted. |
| -f (--fragment) | This means that the rule only refers to second and further IPv4 fragments of fragmented packets. | This means that the rule only refers to second and further IPv4 fragments of fragmented packets. |
| -c (--set-counters) packets bytes | This enables the administrator to initialize the packet and byte counters of a rule (during INSERT,... | This enables the administrator to initialize the packet and byte counters of a rule (during INSERT, APPEND, REPLACE operations). |
Other options (7)
| Shortcut | Action | What it does |
|---|---|---|
| -v (--verbose) | Verbose output. | Verbose output. This option makes the list command show the interface name, the rule options (if any), and the TOS masks. |
| -V (--version) | Show program version and the kernel API used. | Show program version and the kernel API used. |
| -w (--wait) [seconds] | Wait for the xtables lock. | Wait for the xtables lock. To prevent multiple instances of the program from running concurrently, an attempt will be made to obtain an exclusive lock at launch. By default, the program will exit if the lock cannot be obtained. |
| -n (--numeric) | Numeric output. | Numeric output. IP addresses and port numbers will be printed in numeric format. By default, the program will try to display them as host names, network names, or services (whenever applicable). |
| -x (--exact) | Expand numbers. | Expand numbers. Display the exact value of the packet and byte counters, instead of only the rounded number in K's (multiples of 1000), M's (multiples of 1000K) or G's (multiples of 1000M). |
| --line-numbers | When listing rules, add line numbers to the beginning of each rule | The number corresponds to the rule's position in the chain, which is what -D, -I and -R take as rulenum. |
| --modprobe=command | Use command to load any necessary modules when adding or inserting rules | Applies to targets, match extensions and other modules. |
Built-in targets (3)
| Shortcut | Action | What it does |
|---|---|---|
| ACCEPT | Let the packet through | One of the three special built-in target values a rule can jump to with -j (the others are DROP and RETURN). |
| DROP | Drop the packet on the floor | Silently discards the packet; no reply is sent. |
| RETURN | Stop traversing this chain and resume at the next rule in the previous (calling) chain | For a built-in chain, or when the end of a built-in chain is reached, the chain policy decides the packet's fate. |
Frequently Asked Questions
What are the most useful iptables / Firewall shortcuts?
iptables / Firewall has 10 essential shortcuts and commands. Visit the interactive shortcut finder at shortcut-tools.com to search and filter all iptables / Firewall shortcuts by category.
How many iptables / Firewall shortcuts are there?
Our collection includes 10 iptables / Firewall keyboard shortcuts and commands organized by category. New shortcuts are added regularly.
Reading and writing rules
iptables -L -n -v lists every rule with packet counters, numeric addresses and no DNS lookups; add --line-numbers to see the positions that iptables -D INPUT [num] deletes by. Rules are evaluated top to bottom and the first match wins, so iptables -A INPUT -p tcp --dport 80 -j ACCEPT appends to the end and takes effect only if nothing above it dropped the packet; use -I instead of -A to insert at the top. iptables -A INPUT -s [IP] -j DROP blocks a host, and belongs above any broad ACCEPT. iptables -F flushes everything — on a remote server with a default DROP policy this locks you out, so set the policy to ACCEPT first or run it inside a scheduled rollback.
Making it survive a reboot
iptables rules live in the kernel and vanish on reboot. iptables-save > /etc/iptables.rules dumps the current ruleset and iptables-restore < /etc/iptables.rules loads it; Debian and Ubuntu package this as iptables-persistent, and RHEL-family systems use the iptables-services unit with /etc/sysconfig/iptables. Whichever you use, edit the live rules, test, then save — editing the file directly and forgetting to load it is the usual cause of "the rule is there but not working".
ufw
ufw enable turns the firewall on with a default of deny incoming, allow outgoing, and ufw allow [port] opens a port (or a service name such as ssh, or 22/tcp). Allow SSH before enabling on a remote box. ufw status verbose shows the rules and the default policies. ufw writes iptables rules underneath, so iptables -L -n -v shows what it created, but mixing hand-written iptables rules with ufw quickly becomes hard to reason about; pick one.
🤖 Ask AI about iptables / Firewall shortcuts
Open your assistant with this page preloaded as the source — great for follow-up questions like "which of these work in other apps?"