• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
NameHero® Blog

NameHero® Blog

Web Hosting Tips & Resources From NameHero

  • AI Agents
    • OpenClaw
    • Claude Code
    • n8n
    • Hermes Agent
    • Open WebUI
    • Docker
  • Hosting
    • Web Hosting
    • WordPress Hosting
    • WooCommerce Hosting
    • Enterprise Hosting
    • Email Hosting
    • HeroicGuard
    • GPU Hosting
    • Website Builder
  • VPS
    • Managed VPS
    • Unmanaged VPS
    • Flex VPS
  • Reseller
  • Gaming
  • Domains
  • Account
  • Blog Home
  • Categories
  • Authors

How To List Iptables Rules On Linux

CJ Saathoff

Published on: January 1, 2025

Categories: Linux Command Line 0

Do you use Iptables and are looking to check the loaded rules? In this post, we first touch on some background, such as how to make sure you aren’t using a firewall frontend, and then get into checking firewall rules. In this post, we will touch on a few different ways of checking iptables rules from pulling everything to looking at specific sections.

Table of Contents
  • What Is Iptables?
  • What Are Firewall Chains?
  • What Are Iptables Tables?
  • Checking For Firewall Frontends
  • Checking Active Iptables Rules
    • Listing All Firewall Rules
    • Listing A Specific Chain
    • Saving Rules
  • Decoding Rules
  • Checking Iptables, Tables
  • Conclusion
  • Looking For More

What Is Iptables?

The Iptables command is a utility that allows system administrators to configure Linux kernel packet filtering rules. To simplify it acts as a firewall.

What Are Firewall Chains?

Chains are a list of rules that specify how packets are handled.

What Are Iptables Tables?

In Iptables, chains and tables are different concepts, tables are categories that group related chains together for specific functionality (think filtering or NAT).

Checking For Firewall Frontends

Before getting started be aware that you should only be interacting directly with iptables if you aren’t using a firewall frontend, and you aren’t using iptables replacement nftables.

You can use the one-liner below to check if you use the more common firewall front ends.

{ 
    front_end_found=0; WARN="\e[31;1m" RESET="\e[0m"

    # Check if iptables is installed
    command -v iptables >/dev/null || { echo -e "\n${WARN}=== WARNING ===${RESET}\nIptables is not installed. Please install it before proceeding.\n${WARN}================${RESET}\n"; exit 1; }

    # Check for active front-ends
    for cmd in ufw csf firewalld iptables-persistent shorewall apf fail2ban-client; do
        command -v $cmd >/dev/null && { echo -e "\n${WARN}=== WARNING ===${RESET}\n$cmd is active. Avoid direct modifications to iptables rules.\n${WARN}================${RESET}"; front_end_found=1; }
    done

    # Check for nftables if no front-end is active
    [ $front_end_found -eq 0 ] && command -v nft >/dev/null && echo -e "\n${WARN}=== WARNING ===${RESET}\nNftables is installed and is a replacement for iptables. If you encounter issues using iptables please consiter using nftables directly.\n${WARN}================${RESET}\n"
}

Note: This only looks for specific firewall front ends. Please keep this in mind if you aren’t using one defined above.

Checking Active Iptables Rules

Here are some different examples of listing iptables rules.

Listing All Firewall Rules

Below are two different ways to list iptables firewall rules:

iptables --list
iptables -L

Both these function the same, one is just the short form of the other.

Listing A Specific Chain

If you would like to list a specific chain, you can append the chain name to the command like this:

sudo iptables -L [chain_here]

This is really helpful when working with system with large rule sets.

Saving Rules

To list all rules in a way they can be used elsewhere, use the iptables save command iptables-save.

iptables-save

Decoding Rules

Need some help understanding the output here are some of the more common things you will see:

  • Chain Name : Indicates the name of the chain (e.g., INPUT, OUTPUT, FORWARD) for which the rules are listed.
  • Default Policy : Shows the default action taken when packets do not match any rules in this chain (e.g., ACCEPT, DROP). It also includes the number of packets and bytes counted by this default policy.
  • Rule Columns : When options like -v (verbose) and –line-numbers are used, various columns will be present:
    • num : Number of the rule in the chain. This is particularly useful for identifying rules for editing or deletion.
    • pkts : The total number of packets that have matched this rule since it was added.
    • bytes : The total amount of data (in bytes) that has matched this rule since it was added.
    • target : The action taken on a packet that matches this rule (e.g., ACCEPT, DROP, REJECT).
    • prot : The protocol the rule applies to (e.g., TCP, UDP, ICMP). This signifies what kind of traffic the rule is monitoring or filtering.
    • opt : Options related to the protocol being filtered, usually displaying –, indicating that there are no specific options applied in this rule.
    • in : The network interface this rule applies to for incoming packets, where * means all interfaces.
    • out : The network interface this rule applies to for outgoing packets, with * indicating all interfaces.
    • source : The source IP address for packets to which this rule applies. Can be a specific IP address, subnet, or range.
    • destination : The destination IP address or network for packets matching this rule. 0.0.0.0/0 refers to any destination address.

If you don’t see the option above check out the documentation.

Checking Iptables, Tables

To view different tables use the -t flag appended by the table.

The different tables are listed below:

  • filter – General packet filtering.
  • nat – Network Address Translation.
  • mangle – Packet alteration, marking, and QoS.
  • raw – Bypasses connection tracking.
  • security – Implements MAC rules.

So here is an example of listing nat rules:

sudo iptables -t nat -L

Conclusion

Iptables can often seem more complex compared to other firewall solutions. This complexity has led to the development of various front-end interfaces designed to simplify the management of firewall rules. In this post, rather than focusing on those front-end alternatives, we will focus on the necessary background, checking for common iptables frontends, how to list active rules, how to read them, ending with tables in case you’re looking for things not in the default filtering table.

Looking For More

Done and looking for more content why not check out these other firewall related posts?

  • How To Add Or Open Ports In Iptables
  • The UFW Firewall Frontend
  • The CSF Firewall Frontend
CJ Saathoff

Embracing a lifelong passion for technology since childhood, CJ delved into the intricate workings of systems, captivated by the desire to understand the unknown. This innate curiosity led to his discovery of Linux, a revelation that resonated deeply. With more than 7 years of on the job experience, he’s honed his technical skills as a Geek and Senior Linux Systems Administrator.

Related Posts

Bash Debug Mode: set -x and the PS4 Variable

When coding a program, you usually have a full IDE set up with autocomplete and stack tracing, allowing you to pause execution at any point and see what’s going on under the hood. These tools make coding more productive, and they’ve been in use for a long time. But what if you’re just quickly coding […]

How Curl Follows Redirects on Linux

We use curl regularly to fetch resources from websites. Unfortunately, curl doesn't follow redirects automatically. Here's how to fix that.

Linux Process Management: ps, htop, kill, and nice

Linux has a sophisticated toolset to deal with processes in various circumstances from scripting, to monitoring, to control.

Curl Headers, Cookies, and Authentication

You can do a lot more with curl, than just sending requests. Here's how to change the headers, the cookies, and how to authenticate users.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

Follow & Subscribe

Exclusive promos, content and more!


Most Popular Posts

NameHero’s Recommended WordPress Plugin and Theme Setup

WordPress Hosting vs. Web Hosting – What’s The Difference?

How To Increase The InnoDB Buffer Pool Size

How To Fix A Stuck All-in-One WP Migration Import

How To Add A Subdomain In Cloudflare

Top Categories

  • WordPress
  • WordPress Tutorials
  • OpenClaw Hosting
  • Enterprise Hosting
  • WooCommerce
  • Web Hosting
  • Resellers
  • Website Security
  • Website Development
  • Website Performance
  • VPS Hosting
  • SEO Tips
  • Announcements
  • Domain Registration
NameHero

NameHero® proudly provides web hosting to over 40,000 customers with 99.9% uptime to over 750,000 websites.

  • Master Card
  • Visa
  • American Express
  • Discover
  • Paypal
Products
  • Web Hosting
  • Managed VPS Hosting
  • Unmanaged VPS Hosting
  • Flex VPS Hosting
  • WordPress Hosting
  • WooCommerce Hosting
  • Reseller Hosting
  • Enterprise Hosting
  • GPU Hosting
  • Email Hosting
  • HeroicGuard
  • Domains
  • Website Builder
  • AI Agent Hosting
Help & Support
  • NameHero Blog
  • NameHero Gaming Blog
  • Support
  • Help Center
  • Migrations
  • Affiliates
  • Gaming Affiliates
  • Call 1-855-984-6263
Company
  • About Us
  • Contact Sales
  • Reviews
  • Uptime
  • We're Hiring

Copyright © 2026 Name Hero, LLC. All rights reserved.
NameHero® is a registered trademark.

  • Privacy Policy
  • Terms of Use
  • Acceptable Use Policy
  • Payment Policy
  • DMCA