DEV Community

Janak Shrestha
Janak Shrestha

Posted on

Application Security

We have a backup management application UI hosted on Nautilus's backup server in Stratos DC. That backup management application code is deployed under Apache on the backup server itself, and Nginx is running as a reverse proxy on the same server. Apache and Nginx ports are 8088 and 8099, respectively. We have to install the iptables firewall on the server. Make the appropriate changes to fulfill the requirements mentioned below:

We want to open all incoming connections to Nginx's port and block all incoming connections to Apache's port. Also make sure rules are per
Tags: Linux, iptables, Firewall, Security, Nginx, Apache, System Administration, Networkingmanent.


Configuring iptables Firewall on Linux: Allow Nginx and Block Apache

A Complete Step-by-Step Guide for System Administrators


Introduction

Firewall configuration is a critical aspect of server security. In Linux environments, iptables is a powerful tool for controlling incoming and outgoing network traffic. It allows administrators to define rules that determine which connections are allowed and which are blocked.

This guide walks through a real-world scenario where the backup management application on the Nautilus backup server needed specific firewall rules. The goal was to allow all incoming connections to Nginx (port 8099) while blocking all incoming connections to Apache (port 8088), with rules made permanent.


Environment Details

Component Value
Server stbkp01
User clint
Password H@wk3y3
Nginx Port 8099
Apache Port 8088
Purpose Backup management application UI

Understanding iptables

What is iptables

iptables is a command-line firewall utility that uses policy chains to allow or block network traffic. It is part of the Netfilter framework in the Linux kernel and provides a flexible way to define firewall rules.

Key Concepts

Concept Description
Table Collection of chains (filter, nat, mangle)
Chain List of rules (INPUT, OUTPUT, FORWARD)
Rule Condition and action for matching packets
Target Action taken when a rule matches (ACCEPT, DROP, REJECT)
Policy Default action if no rule matches

iptables Chains

Chain Purpose
INPUT Incoming packets to the local system
OUTPUT Outgoing packets from the local system
FORWARD Packets routed through the system

Common Targets

Target Description
ACCEPT Allow the packet to pass
DROP Silently discard the packet
REJECT Discard and send an error response
LOG Log the packet and continue

Prerequisites

Before beginning, ensure the following are available:

  • SSH access to the backup server with sudo or root privileges
  • Knowledge of the ports used by Nginx and Apache
  • Basic understanding of Linux networking

Step 1: Connect to the Backup Server

Access the server using SSH.

ssh clint@stbkp01
Password: H@wk3y3
Enter fullscreen mode Exit fullscreen mode

Switch to root to perform administrative tasks.

sudo su -
Password: H@wk3y3
Enter fullscreen mode Exit fullscreen mode

Step 2: Install iptables

Install the iptables packages using the package manager.

yum install -y iptables iptables-services
Enter fullscreen mode Exit fullscreen mode

The installation may include additional packages depending on the system.

Package Purpose
iptables Core firewall utility
iptables-services Service files for systemd
iptables-legacy Legacy compatibility layer

Verify the installation.

rpm -q iptables-services
Enter fullscreen mode Exit fullscreen mode

Step 3: Check Current iptables Rules

View the current rules before making changes.

iptables -L -n
Enter fullscreen mode Exit fullscreen mode

If the output shows empty chains, no rules are currently defined.

Chain INPUT (policy ACCEPT)
target     prot opt source               destination         

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination         
Enter fullscreen mode Exit fullscreen mode

Step 4: Flush Existing Rules

Clear any existing rules to start with a clean configuration.

iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
Enter fullscreen mode Exit fullscreen mode

Command Breakdown

Command Purpose
iptables -F Flush all rules in the filter table
iptables -X Delete all user-defined chains
iptables -t nat -F Flush rules in the nat table
iptables -t nat -X Delete user-defined chains in nat table

Step 5: Set Default Policies

Set the default policy for each chain. For this task, the default policy is ACCEPT, and specific rules will handle blocking.

iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
Enter fullscreen mode Exit fullscreen mode

Why Start with ACCEPT

Starting with ACCEPT ensures you do not lock yourself out of the server. Specific DROP rules are then added for the ports that need blocking.


Step 6: Allow Established and Related Connections

Allow responses to outgoing connections. Without this rule, the server cannot receive return traffic.

iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Enter fullscreen mode Exit fullscreen mode

This rule is essential for normal network operations, including SSH sessions.


Step 7: Allow Loopback Interface

Allow traffic on the loopback interface for local communication.

iptables -A INPUT -i lo -j ACCEPT
Enter fullscreen mode Exit fullscreen mode

Many services communicate internally via 127.0.0.1. Blocking loopback can cause unexpected failures.


Step 8: Allow SSH

Allow SSH connections to prevent being locked out of the server.

iptables -A INPUT -p tcp --dport 22 -j ACCEPT
Enter fullscreen mode Exit fullscreen mode

Always allow SSH before adding any DROP rules.


Step 9: Allow Nginx Port

Allow all incoming connections to Nginx on port 8099.

iptables -A INPUT -p tcp --dport 8099 -j ACCEPT
Enter fullscreen mode Exit fullscreen mode

Command Breakdown

Option Description
-A INPUT Append rule to INPUT chain
-p tcp Match TCP protocol
--dport 8099 Match destination port 8099
-j ACCEPT Accept matching packets

Step 10: Block Apache Port

Block all incoming connections to Apache on port 8088.

iptables -A INPUT -p tcp --dport 8088 -j DROP
Enter fullscreen mode Exit fullscreen mode

Why DROP Instead of REJECT

Target Behavior Use Case
DROP Silently discards packets Security (hides service existence)
REJECT Sends error response User-friendly (tells client port is closed)

DROP is preferred for security because it does not reveal that a service is running on the port.


Step 11: Save the Rules Permanently

Save the rules so they persist across reboots.

service iptables save
Enter fullscreen mode Exit fullscreen mode

On some systems, the service command may not be available. Use iptables-save instead.

iptables-save > /etc/sysconfig/iptables
Enter fullscreen mode Exit fullscreen mode

Verify the saved rules.

cat /etc/sysconfig/iptables
Enter fullscreen mode Exit fullscreen mode

Expected output.

*filter
:INPUT ACCEPT [34:2440]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [32:4704]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m tcp --dport 8099 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 8088 -j DROP
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
COMMIT
Enter fullscreen mode Exit fullscreen mode

Step 12: Enable the iptables Service

Enable the iptables service to load rules on boot.

systemctl enable iptables
systemctl start iptables
systemctl status iptables
Enter fullscreen mode Exit fullscreen mode

Expected output.

● iptables.service - IPv4 firewall with iptables
     Loaded: loaded (/usr/lib/systemd/system/iptables.service; enabled)
     Active: active (exited) since Tue 2026-09-29 06:17:03 UTC
Enter fullscreen mode Exit fullscreen mode

Step 13: Verify the Rules

List all rules with line numbers.

iptables -L -n --line-numbers
Enter fullscreen mode Exit fullscreen mode

Expected output.

Chain INPUT (policy ACCEPT)
num  target     prot opt source               destination         
1    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
2    ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           
3    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:8099
4    DROP       tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:8088
5    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:22
Enter fullscreen mode Exit fullscreen mode

Step 14: Test the Configuration

Test Nginx (Should Work)

curl -I http://localhost:8099/
Enter fullscreen mode Exit fullscreen mode

Expected output.

HTTP/1.1 200 OK
Server: nginx/1.20.1
Content-Type: text/html
Content-Length: 2713881
Enter fullscreen mode Exit fullscreen mode

Test Apache (Should Be Blocked)

curl -I http://localhost:8088/ --connect-timeout 3
Enter fullscreen mode Exit fullscreen mode

Expected output (external connection).

curl: (7) Failed to connect to localhost port 8088: Connection timed out
Enter fullscreen mode Exit fullscreen mode

Important Note on Local Testing

Testing from localhost may not accurately reflect the DROP rule due to how the loopback interface is handled. To properly test the block, run the curl command from an external host such as the jump host.

# From jump host
curl -I http://stbkp01:8088/ --connect-timeout 3
Enter fullscreen mode Exit fullscreen mode

Complete Workflow Summary

# 1. Connect to server
ssh clint@stbkp01
sudo su -

# 2. Install iptables
yum install -y iptables iptables-services

# 3. Flush existing rules
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X

# 4. Set default policies
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT

# 5. Allow established connections
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

# 6. Allow loopback
iptables -A INPUT -i lo -j ACCEPT

# 7. Allow SSH
iptables -A INPUT -p tcp --dport 22 -j ACCEPT

# 8. Allow Nginx
iptables -A INPUT -p tcp --dport 8099 -j ACCEPT

# 9. Block Apache
iptables -A INPUT -p tcp --dport 8088 -j DROP

# 10. Save rules
iptables-save > /etc/sysconfig/iptables

# 11. Enable service
systemctl enable iptables
systemctl start iptables

# 12. Verify
iptables -L -n --line-numbers
Enter fullscreen mode Exit fullscreen mode

Verification Checklist

Check Command Expected
iptables installed rpm -q iptables-services Installed
Nginx port allowed iptables -L -n | grep 8099 ACCEPT
Apache port blocked iptables -L -n | grep 8088 DROP
Rules saved cat /etc/sysconfig/iptables Rules present
Service enabled systemctl is-enabled iptables enabled
Nginx accessible curl -I http://localhost:8099/ HTTP 200
Apache blocked curl -I http://stbkp01:8088/ Timeout

Troubleshooting Common Issues

Issue 1: service Command Not Found

On newer systems, the service command may be deprecated. Use iptables-save instead.

iptables-save > /etc/sysconfig/iptables
Enter fullscreen mode Exit fullscreen mode

Issue 2: Rules Not Persisting After Reboot

Ensure the iptables service is enabled and the rules are saved.

systemctl enable iptables
iptables-save > /etc/sysconfig/iptables
Enter fullscreen mode Exit fullscreen mode

Issue 3: Locked Out of Server

If you lose SSH access, access the server through the console and flush the rules.

iptables -F
Enter fullscreen mode Exit fullscreen mode

Issue 4: Nginx Not Accessible

Check rule order. Ensure the Nginx ACCEPT rule comes before any DROP rule.

iptables -L -n --line-numbers
Enter fullscreen mode Exit fullscreen mode

Issue 5: Apache Still Accessible Externally

Verify the DROP rule is present and positioned correctly.

iptables -L INPUT -n -v --line-numbers
Enter fullscreen mode Exit fullscreen mode

Best Practices

  1. Always allow SSH before adding any DROP rules.
  2. Test rules from an external host to confirm blocking works.
  3. Save rules immediately after making changes.
  4. Enable the iptables service for persistence.
  5. Use DROP instead of REJECT for security-sensitive ports.
  6. Document firewall rules for audit purposes.
  7. Monitor firewall logs for blocked connection attempts.

Conclusion

This guide covered the complete process of configuring iptables on the backup server to allow Nginx traffic and block Apache traffic permanently. The key steps were installing iptables, flushing existing rules, setting default policies, adding specific allow and block rules, and saving the configuration.

The rules were verified with iptables -L -n --line-numbers and tested with curl. The iptables service was enabled to ensure the rules persist across reboots.

By following these steps, system administrators can implement precise firewall policies that enhance server security while maintaining required service accessibility.


Quick Reference

Task Command
Install iptables yum install -y iptables iptables-services
Flush rules iptables -F
Allow port iptables -A INPUT -p tcp --dport PORT -j ACCEPT
Block port iptables -A INPUT -p tcp --dport PORT -j DROP
Save rules iptables-save > /etc/sysconfig/iptables
Enable service systemctl enable iptables
Start service systemctl start iptables
List rules iptables -L -n --line-numbers
Test Nginx curl -I http://localhost:8099/
Test Apache curl -I http://stbkp01:8088/

This guide was created based on a real-world iptables configuration task on the Nautilus Backup Server in the Stratos Datacenter.

Top comments (0)