VPS1Euro Dashboard Wiki

Complete client guide: infrastructure, services, account and support.

FR EN

Firewall with iptables

Secure the container by filtering incoming and outgoing network traffic.

What this tutorial does

The tutorial "Firewall with iptables" helps you achieve this goal:

Secure the container by filtering incoming and outgoing network traffic.

← Back to tutorials
1 profiles 25 steps 16 commands ~30 min

Debian/Ubuntu

  1. Install iptables-persistent: apt install -y iptables-persistent
  2. --- Reset rules ---
  3. iptables -F && iptables -X
  4. --- Default policy (block all input) ---
  5. iptables -P INPUT DROP
  6. iptables -P FORWARD DROP
  7. iptables -P OUTPUT ACCEPT
  8. --- Allow already established connections ---
  9. iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
  10. --- Allow loopback ---
  11. iptables -A INPUT -i lo -j ACCEPT
  12. --- Allow SSH (port 22) ---
  13. iptables -A INPUT -p tcp --dport 22 -j ACCEPT
  14. --- Allow HTTP and HTTPS ---
  15. iptables -A INPUT -p tcp --dport 80 -j ACCEPT
  16. iptables -A INPUT -p tcp --dport 443 -j ACCEPT
  17. --- Allow ICMP pings ---
  18. iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
  19. --- Limit SSH connection attempts (anti brute-force) ---
  20. iptables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --set
  21. iptables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 -j DROP
  22. --- Save rules (persistent on restart) ---
  23. netfilter-persistent save
  24. --- Check active rules ---
  25. iptables -L -v -n --line-numbers