## Configure the Linux firewall (netfilter) for IPv4

# List rules
sudo iptables -L

# List rules with counters, numbers and no DNS lookups
sudo iptables -L -n -v --line-numbers

# Show rules as commands (easy to copy)
sudo iptables -S

# Show NAT rules
sudo iptables -t nat -L -n -v

# Allow loopback traffic
sudo iptables -A INPUT -i lo -j ACCEPT

# Allow replies to connections you started
sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

# Drop invalid packets
sudo iptables -A INPUT -m conntrack --ctstate INVALID -j DROP

# Allow SSH
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT

# Allow HTTP and HTTPS in one rule
sudo iptables -A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT

# Allow ping
sudo iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT

# Default deny incoming (allow SSH FIRST or you lock yourself out)
sudo iptables -P INPUT DROP

# Allow a database port only from the private network
sudo iptables -A INPUT -p tcp -s 10.0.0.0/8 --dport 5432 -j ACCEPT

# Allow a port only on one interface
sudo iptables -A INPUT -i eth1 -p tcp --dport 3306 -j ACCEPT

# Block an IP address
sudo iptables -A INPUT -s 203.0.113.50 -j DROP

# Block a whole subnet
sudo iptables -A INPUT -s 203.0.113.0/24 -j DROP

# Block a MAC address
sudo iptables -A INPUT -m mac --mac-source 00:11:22:33:44:55 -j DROP

# Reject instead of silently dropping
sudo iptables -A INPUT -p tcp --dport 23 -j REJECT --reject-with tcp-reset

# Insert a rule at the top of the chain
sudo iptables -I INPUT 1 -s 198.51.100.7 -j ACCEPT

# Delete a rule by its number
sudo iptables -D INPUT 3

# Delete a rule by its definition
sudo iptables -D INPUT -s 203.0.113.50 -j DROP

# Brute-force protection: max 5 new SSH connections per minute per IP
sudo iptables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --set
sudo iptables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --update --seconds 60 --hitcount 5 -j DROP

# Rate-limit ping
sudo iptables -A INPUT -p icmp -m limit --limit 1/second -j ACCEPT

# Log packets before they are dropped
sudo iptables -A INPUT -j LOG --log-prefix "IPT-DROP: " --log-level 4

# Forward port 80 to another machine
sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination 10.0.0.10:8080

# Redirect port 80 to local port 8080
sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080

# Share internet (NAT) from eth0 for a private network
sudo sysctl -w net.ipv4.ip_forward=1
sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

# Allow forwarding from the internal to the external interface
sudo iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT

# Reset packet counters
sudo iptables -Z

# Delete all rules (check the default policy first!)
sudo iptables -F

# Save rules to a file
sudo iptables-save > /etc/iptables/rules.v4

# Restore rules from a file
sudo iptables-restore < /etc/iptables/rules.v4

# Keep rules after reboot (Debian/Ubuntu)
sudo apt install iptables-persistent
sudo netfilter-persistent save

# Apply rules with automatic rollback if you lose access
sudo iptables-apply /etc/iptables/rules.v4

# Same commands for IPv6
sudo ip6tables -L -n -v
