Firewall with iptables
Secure the container by filtering incoming and outgoing network traffic.
What this tutorial does
The tutorial "Firewall with iptables" helps you achieve this goal:
Secure the container by filtering incoming and outgoing network traffic.
Debian/Ubuntu
-
Install iptables-persistent: apt install -y iptables-persistent - --- Reset rules ---
-
iptables -F && iptables -X - --- Default policy (block all input) ---
-
iptables -P INPUT DROP -
iptables -P FORWARD DROP -
iptables -P OUTPUT ACCEPT - --- Allow already established connections ---
-
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT - --- Allow loopback ---
-
iptables -A INPUT -i lo -j ACCEPT -
--- Allow SSH (port 22) --- -
iptables -A INPUT -p tcp --dport 22 -j ACCEPT - --- Allow HTTP and HTTPS ---
-
iptables -A INPUT -p tcp --dport 80 -j ACCEPT -
iptables -A INPUT -p tcp --dport 443 -j ACCEPT - --- Allow ICMP pings ---
-
iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT -
--- Limit SSH connection attempts (anti brute-force) --- -
iptables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --set -
iptables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 -j DROP - --- Save rules (persistent on restart) ---
- netfilter-persistent save
- --- Check active rules ---
-
iptables -L -v -n --line-numbers