How to Implement firewall rules with iptables on AlmaLinux 9

Estimated reading: 3 minutes 414 views

Implementing firewall rules with iptables on AlmaLinux 9 involves configuring the Linux kernel’s netfilter framework to control network traffic based on predefined rules. AlmaLinux 9 uses firewalld as the default firewall management tool, which interfaces with nftables rather than iptables. However, iptables can still be used for granular control, though it requires careful setup to avoid conflicts with firewalld. Below is a detailed, step-by-step guide to implementing firewall rules with iptables on AlmaLinux 9, adhering to a formal tone and best practices.

Prerequisites

  • Root or sudo privileges on AlmaLinux 9.
  • Firewalld is disabled to avoid conflicts:
    systemctl stop firewalld
    systemctl disable firewalld
  • Knowledge of network interfaces, IP addresses, and services to allow/block.

Step-by-Step Guide to Implementing iptables Firewall Rules

Step 1: Install iptables

Most modern Linux distributions, including AlmaLinux, come with iptables installed by default. You can verify its installation by running:

dnf install iptables iptables-services -y

Step 2: Enable and Start iptables

Enable the iptables service to start on boot and start the service:

systemctl enable iptables
systemctl start iptables

Verify Installation:

iptables -V


Step 3: Basic Iptables Commands

List current rules:

iptables -L -v


Add a rule:

iptables -A INPUT -p tcp --dport 22 -j ACCEPT

Delete a rule:

iptables -D INPUT -p tcp --dport 22 -j ACCEPT

Save rules:

service iptables save

Restore rules:

service iptables restart

Step 4: Example Iptables Configuration

Here’s an example of a basic iptables configuration:

Flush existing rules:

iptables -F

Set default policies:

Caution with the following commands. It will disconnect you from your server.

iptables -P INPUT DROP 
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT

Allow loopback traffic:

iptables -A INPUT -i lo -j ACCEPT

Allow established and related connections:

iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

Allow SSH connections:

iptables -A INPUT -p tcp --dport 22 -j ACCEPT

Allow HTTP and HTTPS connections:

iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j ACCEPT

Save the rules:

service iptables save

Step 5: Persisting Rules Across Reboots

To ensure your iptables rules persist across reboots, save the rules using:

service iptables save

The rules will be saved in /etc/sysconfig/iptables.

Step 6: Managing iptables with Scripts

For more complex setups, you can create a script to manage your iptables rules. Create a script, and add your rules there:

nano iptables.rules

Add the following script:

#!/bin/bash

# Flush existing rules
iptables -F

# Set default policies
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT

# Allow loopback traffic
iptables -A INPUT -i lo -j ACCEPT

# Allow established and related connections
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

# Allow SSH
iptables -A INPUT -p tcp --dport 22 -j ACCEPT

# Allow HTTP and HTTPS
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j ACCEPT
iptables -A INPUT -p tcp --dport 8080 -j ACCEPT  #add for custom ports
iptables -A INPUT -p tcp --dport 3000 -j ACCEPT   #add for custom ports

# Save rules
service iptables save

Save and exit

Make the script executable:

chmod +x iptables.rules

Run the script to apply the rules:

./iptables.rules

Step 7: Verify Configuration

Verify your iptables configuration:

iptables -L -v


This guide should help you set up and manage iptables on AlmaLinux 9. Adjust the rules as per your specific requirements.

Share this Doc

How to Implement firewall rules with iptables on AlmaLinux 9

Or copy link

CONTENTS