↑ ↓ select, Enter open, Esc close

Firewall

Open and close ports, check rules, block and unblock IPs. With ufw for a quick start, nftables for full control and CrowdSec for community-maintained blocklists.

21 one-liners: 8 harmless, 11 caution, 2 destructive

All Firewall one-liners

Add an IP address to an nftables blocklist

#nft add element inet filter blocklist '{ 203.0.113.25 }'
caution

Allow a port only from a specific IP with ufw

#ufw allow from 198.51.100.0/24 to any port 22 proto tcp
caution

Back up iptables rules to a file

#iptables-save > /root/iptables-$(date +%F-%H%M).rules
harmless

Ban an IP address manually in CrowdSec

#cscli decisions add --ip 203.0.113.25 --duration 24h --reason 'manual ban'
caution

Block an IP address or subnet with ufw

#ufw insert 1 deny from 203.0.113.0/24
caution

Close a port in ufw by deleting its rule

#ufw delete allow 8080/tcp
caution

For the websites on your server

Free SEO and PageSpeed check

GENLOC.SEO analyzes any domain for load time, Core Web Vitals and on-page issues and tells you in plain words what is going on. Available in 11 languages.

by GENLOC.NETWORK, the team behind myline.de

Count IP addresses blocked by ufw

#journalctl -k --since "today" --no-pager | grep 'UFW BLOCK' | grep -o 'SRC=[^ ]*' | sort | uniq -c | sort -rn | head -20
harmless

Create an IP blocklist set in nftables

#nft add set inet filter blocklist '{ type ipv4_addr; flags interval; }' && nft insert rule inet filter input ip saddr @blocklist drop
caution

Delete a ufw rule by number

#ufw delete 3
caution

Enable ufw logging

#ufw logging low
caution

Enable ufw without locking yourself out

#ufw allow 22/tcp && ufw enable
destructive

List ufw rules with numbers

#ufw status numbered
harmless

Open a port with nftables

#nft insert rule inet filter input tcp dport 443 accept
caution

Open a port with ufw

#ufw allow 443/tcp
caution

Restore iptables rules from a backup

#iptables-restore --test < /root/iptables-2026-10-09-1200.rules && iptables-restore < /root/iptables-2026-10-09-1200.rules
destructive

Show active CrowdSec decisions and bans

#cscli decisions list
harmless

Show CrowdSec alerts

#cscli alerts list
harmless

Show CrowdSec metrics for logs, parsers and bouncers

#cscli metrics
harmless

Show detailed ufw status and default policies

#ufw status verbose
harmless

Show the complete nftables ruleset with handles

#nft -a list ruleset
harmless

Unban an IP address in CrowdSec

#cscli decisions delete --ip 198.51.100.10
caution

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.