#firewall
18 one-liners with this tag.
All one-liners tagged firewall
Allow a port only from a specific IP with ufw
#ufw allow from 198.51.100.0/24 to any port 22 proto tcp
Back up iptables rules to a file
#iptables-save > /root/iptables-$(date +%F-%H%M).rules
Block a single IP address immediately with iptables
#iptables -I INPUT -s 203.0.113.25 -j DROP
Block an IP address or subnet with ufw
#ufw insert 1 deny from 203.0.113.0/24
Check server ports from outside with nmap
$nmap -Pn -p 21,22,25,80,110,143,443,465,587,993,995,3306,8443,8880 server.example.com
Close a port in ufw by deleting its rule
#ufw delete allow 8080/tcp
Count IP addresses blocked by ufw
#journalctl -k --since "today" --no-pager | grep 'UFW BLOCK' | grep -o 'SRC=[^ ]*' | sort | uniq -c | sort -rn | head -20
Create an IP blocklist set in nftables
#nft add set inet filter blocklist '{ type ipv4_addr; flags interval; }' && nft insert rule inet filter input ip saddr @blocklist drop
Delete a ufw rule by number
#ufw delete 3
Enable ufw logging
#ufw logging low
Enable ufw without locking yourself out
#ufw allow 22/tcp && ufw enable
List ufw rules with numbers
#ufw status numbered
Open a port with nftables
#nft insert rule inet filter input tcp dport 443 accept
Open a port with ufw
#ufw allow 443/tcp
Restore iptables rules from a backup
#iptables-restore --test < /root/iptables-2026-10-09-1200.rules && iptables-restore < /root/iptables-2026-10-09-1200.rules
Show detailed ufw status and default policies
#ufw status verbose
Show the complete nftables ruleset with handles
#nft -a list ruleset
Test if a TCP port is reachable without telnet or nc
$timeout 3 bash -c '</dev/tcp/db.example.com/3306' && echo offen || echo "geschlossen oder gefiltert"