We have a backup management application UI hosted on Nautilus's backup server in Stratos DC. That backup management application code is deployed under Apache on the backup server itself, and Nginx is running as a reverse proxy on the same server. Apache and Nginx ports are 8088 and 8099, respectively. We have to install the iptables firewall on the server. Make the appropriate changes to fulfill the requirements mentioned below:
We want to open all incoming connections to Nginx's port and block all incoming connections to Apache's port. Also make sure rules are per
Tags: Linux, iptables, Firewall, Security, Nginx, Apache, System Administration, Networkingmanent.
Configuring iptables Firewall on Linux: Allow Nginx and Block Apache
A Complete Step-by-Step Guide for System Administrators
Introduction
Firewall configuration is a critical aspect of server security. In Linux environments, iptables is a powerful tool for controlling incoming and outgoing network traffic. It allows administrators to define rules that determine which connections are allowed and which are blocked.
This guide walks through a real-world scenario where the backup management application on the Nautilus backup server needed specific firewall rules. The goal was to allow all incoming connections to Nginx (port 8099) while blocking all incoming connections to Apache (port 8088), with rules made permanent.
Environment Details
| Component | Value |
|---|---|
| Server | stbkp01 |
| User | clint |
| Password | H@wk3y3 |
| Nginx Port | 8099 |
| Apache Port | 8088 |
| Purpose | Backup management application UI |
Understanding iptables
What is iptables
iptables is a command-line firewall utility that uses policy chains to allow or block network traffic. It is part of the Netfilter framework in the Linux kernel and provides a flexible way to define firewall rules.
Key Concepts
| Concept | Description |
|---|---|
| Table | Collection of chains (filter, nat, mangle) |
| Chain | List of rules (INPUT, OUTPUT, FORWARD) |
| Rule | Condition and action for matching packets |
| Target | Action taken when a rule matches (ACCEPT, DROP, REJECT) |
| Policy | Default action if no rule matches |
iptables Chains
| Chain | Purpose |
|---|---|
| INPUT | Incoming packets to the local system |
| OUTPUT | Outgoing packets from the local system |
| FORWARD | Packets routed through the system |
Common Targets
| Target | Description |
|---|---|
| ACCEPT | Allow the packet to pass |
| DROP | Silently discard the packet |
| REJECT | Discard and send an error response |
| LOG | Log the packet and continue |
Prerequisites
Before beginning, ensure the following are available:
- SSH access to the backup server with sudo or root privileges
- Knowledge of the ports used by Nginx and Apache
- Basic understanding of Linux networking
Step 1: Connect to the Backup Server
Access the server using SSH.
ssh clint@stbkp01
Password: H@wk3y3
Switch to root to perform administrative tasks.
sudo su -
Password: H@wk3y3
Step 2: Install iptables
Install the iptables packages using the package manager.
yum install -y iptables iptables-services
The installation may include additional packages depending on the system.
| Package | Purpose |
|---|---|
| iptables | Core firewall utility |
| iptables-services | Service files for systemd |
| iptables-legacy | Legacy compatibility layer |
Verify the installation.
rpm -q iptables-services
Step 3: Check Current iptables Rules
View the current rules before making changes.
iptables -L -n
If the output shows empty chains, no rules are currently defined.
Chain INPUT (policy ACCEPT)
target prot opt source destination
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Step 4: Flush Existing Rules
Clear any existing rules to start with a clean configuration.
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
Command Breakdown
| Command | Purpose |
|---|---|
| iptables -F | Flush all rules in the filter table |
| iptables -X | Delete all user-defined chains |
| iptables -t nat -F | Flush rules in the nat table |
| iptables -t nat -X | Delete user-defined chains in nat table |
Step 5: Set Default Policies
Set the default policy for each chain. For this task, the default policy is ACCEPT, and specific rules will handle blocking.
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
Why Start with ACCEPT
Starting with ACCEPT ensures you do not lock yourself out of the server. Specific DROP rules are then added for the ports that need blocking.
Step 6: Allow Established and Related Connections
Allow responses to outgoing connections. Without this rule, the server cannot receive return traffic.
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
This rule is essential for normal network operations, including SSH sessions.
Step 7: Allow Loopback Interface
Allow traffic on the loopback interface for local communication.
iptables -A INPUT -i lo -j ACCEPT
Many services communicate internally via 127.0.0.1. Blocking loopback can cause unexpected failures.
Step 8: Allow SSH
Allow SSH connections to prevent being locked out of the server.
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
Always allow SSH before adding any DROP rules.
Step 9: Allow Nginx Port
Allow all incoming connections to Nginx on port 8099.
iptables -A INPUT -p tcp --dport 8099 -j ACCEPT
Command Breakdown
| Option | Description |
|---|---|
| -A INPUT | Append rule to INPUT chain |
| -p tcp | Match TCP protocol |
| --dport 8099 | Match destination port 8099 |
| -j ACCEPT | Accept matching packets |
Step 10: Block Apache Port
Block all incoming connections to Apache on port 8088.
iptables -A INPUT -p tcp --dport 8088 -j DROP
Why DROP Instead of REJECT
| Target | Behavior | Use Case |
|---|---|---|
| DROP | Silently discards packets | Security (hides service existence) |
| REJECT | Sends error response | User-friendly (tells client port is closed) |
DROP is preferred for security because it does not reveal that a service is running on the port.
Step 11: Save the Rules Permanently
Save the rules so they persist across reboots.
service iptables save
On some systems, the service command may not be available. Use iptables-save instead.
iptables-save > /etc/sysconfig/iptables
Verify the saved rules.
cat /etc/sysconfig/iptables
Expected output.
*filter
:INPUT ACCEPT [34:2440]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [32:4704]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m tcp --dport 8099 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 8088 -j DROP
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
COMMIT
Step 12: Enable the iptables Service
Enable the iptables service to load rules on boot.
systemctl enable iptables
systemctl start iptables
systemctl status iptables
Expected output.
● iptables.service - IPv4 firewall with iptables
Loaded: loaded (/usr/lib/systemd/system/iptables.service; enabled)
Active: active (exited) since Tue 2026-09-29 06:17:03 UTC
Step 13: Verify the Rules
List all rules with line numbers.
iptables -L -n --line-numbers
Expected output.
Chain INPUT (policy ACCEPT)
num target prot opt source destination
1 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
2 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
3 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8099
4 DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8088
5 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
Step 14: Test the Configuration
Test Nginx (Should Work)
curl -I http://localhost:8099/
Expected output.
HTTP/1.1 200 OK
Server: nginx/1.20.1
Content-Type: text/html
Content-Length: 2713881
Test Apache (Should Be Blocked)
curl -I http://localhost:8088/ --connect-timeout 3
Expected output (external connection).
curl: (7) Failed to connect to localhost port 8088: Connection timed out
Important Note on Local Testing
Testing from localhost may not accurately reflect the DROP rule due to how the loopback interface is handled. To properly test the block, run the curl command from an external host such as the jump host.
# From jump host
curl -I http://stbkp01:8088/ --connect-timeout 3
Complete Workflow Summary
# 1. Connect to server
ssh clint@stbkp01
sudo su -
# 2. Install iptables
yum install -y iptables iptables-services
# 3. Flush existing rules
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
# 4. Set default policies
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
# 5. Allow established connections
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
# 6. Allow loopback
iptables -A INPUT -i lo -j ACCEPT
# 7. Allow SSH
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
# 8. Allow Nginx
iptables -A INPUT -p tcp --dport 8099 -j ACCEPT
# 9. Block Apache
iptables -A INPUT -p tcp --dport 8088 -j DROP
# 10. Save rules
iptables-save > /etc/sysconfig/iptables
# 11. Enable service
systemctl enable iptables
systemctl start iptables
# 12. Verify
iptables -L -n --line-numbers
Verification Checklist
| Check | Command | Expected |
|---|---|---|
| iptables installed | rpm -q iptables-services | Installed |
| Nginx port allowed | iptables -L -n | grep 8099 | ACCEPT |
| Apache port blocked | iptables -L -n | grep 8088 | DROP |
| Rules saved | cat /etc/sysconfig/iptables | Rules present |
| Service enabled | systemctl is-enabled iptables | enabled |
| Nginx accessible | curl -I http://localhost:8099/ | HTTP 200 |
| Apache blocked | curl -I http://stbkp01:8088/ | Timeout |
Troubleshooting Common Issues
Issue 1: service Command Not Found
On newer systems, the service command may be deprecated. Use iptables-save instead.
iptables-save > /etc/sysconfig/iptables
Issue 2: Rules Not Persisting After Reboot
Ensure the iptables service is enabled and the rules are saved.
systemctl enable iptables
iptables-save > /etc/sysconfig/iptables
Issue 3: Locked Out of Server
If you lose SSH access, access the server through the console and flush the rules.
iptables -F
Issue 4: Nginx Not Accessible
Check rule order. Ensure the Nginx ACCEPT rule comes before any DROP rule.
iptables -L -n --line-numbers
Issue 5: Apache Still Accessible Externally
Verify the DROP rule is present and positioned correctly.
iptables -L INPUT -n -v --line-numbers
Best Practices
- Always allow SSH before adding any DROP rules.
- Test rules from an external host to confirm blocking works.
- Save rules immediately after making changes.
- Enable the iptables service for persistence.
- Use DROP instead of REJECT for security-sensitive ports.
- Document firewall rules for audit purposes.
- Monitor firewall logs for blocked connection attempts.
Conclusion
This guide covered the complete process of configuring iptables on the backup server to allow Nginx traffic and block Apache traffic permanently. The key steps were installing iptables, flushing existing rules, setting default policies, adding specific allow and block rules, and saving the configuration.
The rules were verified with iptables -L -n --line-numbers and tested with curl. The iptables service was enabled to ensure the rules persist across reboots.
By following these steps, system administrators can implement precise firewall policies that enhance server security while maintaining required service accessibility.
Quick Reference
| Task | Command |
|---|---|
| Install iptables | yum install -y iptables iptables-services |
| Flush rules | iptables -F |
| Allow port | iptables -A INPUT -p tcp --dport PORT -j ACCEPT |
| Block port | iptables -A INPUT -p tcp --dport PORT -j DROP |
| Save rules | iptables-save > /etc/sysconfig/iptables |
| Enable service | systemctl enable iptables |
| Start service | systemctl start iptables |
| List rules | iptables -L -n --line-numbers |
| Test Nginx | curl -I http://localhost:8099/ |
| Test Apache | curl -I http://stbkp01:8088/ |
This guide was created based on a real-world iptables configuration task on the Nautilus Backup Server in the Stratos Datacenter.
Top comments (0)