↑ ↓ select, Enter open, Esc close

#firewall

18 one-liners with this tag.

All one-liners tagged firewall

Allow a port only from a specific IP with ufw

#ufw allow from 198.51.100.0/24 to any port 22 proto tcp
cautionFirewall

Back up iptables rules to a file

#iptables-save > /root/iptables-$(date +%F-%H%M).rules
harmlessFirewall

Block a single IP address immediately with iptables

#iptables -I INPUT -s 203.0.113.25 -j DROP
cautionSecurity

Block an IP address or subnet with ufw

#ufw insert 1 deny from 203.0.113.0/24
cautionFirewall

Check server ports from outside with nmap

$nmap -Pn -p 21,22,25,80,110,143,443,465,587,993,995,3306,8443,8880 server.example.com
harmlessNetwork

Close a port in ufw by deleting its rule

#ufw delete allow 8080/tcp
cautionFirewall

Count IP addresses blocked by ufw

#journalctl -k --since "today" --no-pager | grep 'UFW BLOCK' | grep -o 'SRC=[^ ]*' | sort | uniq -c | sort -rn | head -20
harmlessFirewall

Create an IP blocklist set in nftables

#nft add set inet filter blocklist '{ type ipv4_addr; flags interval; }' && nft insert rule inet filter input ip saddr @blocklist drop
cautionFirewall

Delete a ufw rule by number

#ufw delete 3
cautionFirewall

Enable ufw logging

#ufw logging low
cautionFirewall

Enable ufw without locking yourself out

#ufw allow 22/tcp && ufw enable
destructiveFirewall

List ufw rules with numbers

#ufw status numbered
harmlessFirewall

Open a port with nftables

#nft insert rule inet filter input tcp dport 443 accept
cautionFirewall

Open a port with ufw

#ufw allow 443/tcp
cautionFirewall

Restore iptables rules from a backup

#iptables-restore --test < /root/iptables-2026-10-09-1200.rules && iptables-restore < /root/iptables-2026-10-09-1200.rules
destructiveFirewall

Show detailed ufw status and default policies

#ufw status verbose
harmlessFirewall

Show the complete nftables ruleset with handles

#nft -a list ruleset
harmlessFirewall

Test if a TCP port is reachable without telnet or nc

$timeout 3 bash -c '</dev/tcp/db.example.com/3306' && echo offen || echo "geschlossen oder gefiltert"
harmlessNetwork

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.