Small bash helpers around iptables for common tasks:
- Open or close ports on the INPUT chain.
- Add or remove simple destination NAT port-forwarding rules.
- Create, list, view, and restore iptables backups.
firewall-ip-allow/ip-firewall-add.sh– allow one or more ports on INPUT.ip-firewall-remove.sh– remove rules that match a given port.
ip-fowarding/ip-foward-add.sh– add IPv4 DNAT + MASQUERADE port forward.ip-foward-remove.sh– remove an existing port forward.
iptables-backup/backup-iptables.sh– simple TUI for iptables backups.
Warning
the scipts won't work if you are using nftables as backend for iptables, or if your system uses firewalld, ufw or another firewall manager that conflicts with direct iptables manipulation.
Please consult your default firewall management tool for how to disable it first.
Example:
ufw disable
systemctl stop ufw
systemctl disable ufw-
Linux host with
iptablesavailable and thenattable enabled. -
Root privileges (most scripts exit if not run as root).
-
For port forwarding, the destination host must be reachable from this machine.
-
Make sure to allow running with:
chmod +x firewall-ip-allow/ip-firewall-add.sh
chmod +x firewall-ip-allow/ip-firewall-remove.sh
chmod +x ip-fowarding/ip-foward-add.sh
chmod +x ip-fowarding/ip-foward-remove.sh
chmod +x iptables-backup/backup-iptables.shWarning
For DNAT port forwarding you must enable IPv4 forwarding:
sudo sysctl -w net.ipv4.ip_forward=1Directory: firewall-ip-allow/
Interactively inserts INPUT rules to allow one or more ports.
cd firewall-ip-allow
sudo ./ip-firewall-add.shYou will be prompted for:
- Port numbers (comma separated), e.g.
80,443, 8080. - Protocol:
tcp,udp, orboth(default isboth).
For each port, the script inserts rules near the top of INPUT, using -m conntrack --ctstate NEW for TCP to only allow new connections.
Removes any rules that reference a given port, based on iptables-save output.
cd firewall-ip-allow
sudo ./ip-firewall-remove.shYou will be prompted for a single port number. All matching rules containing that port are translated from -A ... to iptables -D ... and deleted.
Directory: ip-fowarding/ (IPv4 only).
These helpers configure destination NAT (DNAT) with MASQUERADE and the necessary FORWARD rules for a single external port mapped to a host/port behind this machine.
cd ip-fowarding
sudo ./ip-foward-add.shPrompts for:
- Incoming port (public).
- Destination IP (internal/target host).
- Destination port.
For both TCP and UDP it will:
- Add a
PREROUTINGrule in thenattable with DNAT. - Add a
POSTROUTINGMASQUERADErule in thenattable. - Add matching
FORWARDrules (NEW/ESTABLISHED/RELATED flows in both directions).
cd ip-fowarding
sudo ./ip-foward-remove.shThe script:
- Lists
PREROUTINGDNAT rules (with line numbers). - Asks for the rule number to remove (usually twice – once for TCP and once for UDP).
- Derives protocol, ports, and destination from that rule.
- Deletes the selected
PREROUTINGline plus relatedPOSTROUTINGMASQUERADE andFORWARDrules. - Performs some additional cleanup deletions and ignores errors if rules are already gone.
Rules created by ip-foward-add.sh are ephemeral; they are lost on reboot unless saved.
Directory: iptables-backup/
backup-iptables.sh is a small interactive helper to manage rule snapshots under $HOME/iptables_backups.
cd iptables-backup
sudo ./backup-iptables.shMain menu:
1) Create new backup– runsiptables-saveand writes a timestamped*.rulesfile.2) View/Restore backups– lists the latest backups (up to 20), lets you:- View contents of a selected file.
- Restore from a backup via
iptables-restore(with confirmation prompt).
0) Exit– quit the tool.
Restoring a backup overwrites your current iptables ruleset, so double-check the file you pick.
Create a file in /usr/local/bin/iptables-tools with the following content:
#!/bin/bash
set -e
BASE="/root/iptables-tools"
usage() {
cat <<EOF
Usage:
iptables-tools firewall add
iptables-tools firewall remove
iptables-tools forward add
iptables-tools forward remove
iptables-tools backup
EOF
}
case "$1" in
firewall)
case "$2" in
add) exec "$BASE/firewall-ip-allow/ip-firewall-add.sh" ;;
remove) exec "$BASE/firewall-ip-allow/ip-firewall-remove.sh" ;;
*) usage ;;
esac
;;
forward|foward) # accept typo, because reality
case "$2" in
add) exec "$BASE/ip-fowarding/ip-foward-add.sh" ;;
remove) exec "$BASE/ip-fowarding/ip-foward-remove.sh" ;;
*) usage ;;
esac
;;
backup)
exec "$BASE/iptables-backup/backup-iptables.sh"
;;
-h|--help|"")
usage
;;
*)
echo "Unknown command"
usage
;;
esacMake it executable:
chmod +x /usr/local/bin/iptables-tools_iptables_tools() {
local cur prev
cur="${COMP_WORDS[COMP_CWORD]}"
prev="${COMP_WORDS[COMP_CWORD-1]}"
case "${COMP_CWORD}" in
1)
COMPREPLY=( $(compgen -W "firewall forward foward backup" -- "$cur") )
;;
2)
case "${COMP_WORDS[1]}" in
firewall|forward|foward)
COMPREPLY=( $(compgen -W "add remove" -- "$cur") )
;;
backup)
COMPREPLY=()
;;
esac
;;
esac
}
complete -F _iptables_tools iptables-toolsRead the completion file:
source /etc/bash_completionCommands are as follows:
iptables-tools firewall add
iptables-tools firewall remove
iptables-tools forward add
iptables-tools forward remove
iptables-tools backup- All changes are made directly with
iptables; they are not persisted unless you save them separately (e.g. withiptables-save/iptables-restoreor your distro's firewall tooling). - Run these scripts via
sudoor as root; otherwise some operations will fail. - Always test from a remote shell you can recover from (e.g. a second SSH session) when modifying firewall rules, to avoid locking yourself out.