pkg.soopen package index

brew / rank 5927

Install iptables with Homebrew, apk, apt, Nix, pacman, zypper, dnf

Linux kernel packet control tool. Version 1.8.13 via Homebrew; verified from local package data. Also installable with debian: sudo apt install iptables.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install iptables

local Homebrew formula metadata

Linux

Alpine Linux apkverified · 92%
sudo apk add iptables

Alpine Linux edge package indexes · iptables · source: dl-cdn.alpinelinux.org

Debian aptverified · 92%
sudo apt install iptables

Debian stable package indexes · iptables · source: deb.debian.org

Nixverified · 92%
nix profile install nixpkgs#iptables

nixpkgs package indexes · pkgs/by-name/ip/iptables/package.nix · source: api.github.com

Arch Linux pacmanverified · 92%
sudo pacman -S iptables

Arch Linux sync databases · iptables · source: geo.mirror.pkgbuild.com

openSUSE zypperverified · 92%
sudo zypper install iptables

openSUSE Tumbleweed package metadata · iptables · source: download.opensuse.org

Fedora dnfverified · 92%
sudo dnf install iptables-devel

Fedora Rawhide package metadata · iptables-devel · source: dl.fedoraproject.org

overview

Package summary

Linux kernel packet control tool

Commands and aliases

  • arptables
  • arptables-nft
  • arptables-nft-restore
  • arptables-nft-save
  • arptables-restore
  • arptables-save
  • arptables-translate
  • ebtables
  • ebtables-nft
  • ebtables-nft-restore
  • ebtables-nft-save
  • ebtables-restore
  • ebtables-save
  • ebtables-translate
  • ip6tables
  • ip6tables-apply
  • ip6tables-legacy
  • ip6tables-legacy-restore
  • ip6tables-legacy-save
  • ip6tables-nft
  • ip6tables-nft-restore
  • ip6tables-nft-save
  • ip6tables-restore
  • ip6tables-restore-translate
  • ip6tables-save
  • ip6tables-translate
  • iptables
  • iptables-apply
  • iptables-legacy
  • iptables-legacy-restore
  • iptables-legacy-save
  • iptables-nft

history

Project history and usage

iptables is the long-lived user-space command family for controlling Linux packet filtering, NAT, and mangling rules through the netfilter framework. It sits at the intersection of kernel networking, firewall administration, and distribution packaging, with companion commands such as ip6tables, arptables, ebtables, restore/save tools, and nft translation frontends.

Project history

The netfilter project was founded by Paul "Rusty" Russell as a redesign of the Linux 2.2 ipchains and Linux 2.0 ipfwadm firewall systems. Netfilter's own project history describes the late-1999 design work by Russell and Marc Boucher that generalized iptables and produced the multiple-table framework that became the filter, nat, and mangle modules.

iptables became the administrative surface for the Linux 2.4 era of packet filtering. The project grew alongside connection tracking, NAT helpers, userspace queueing, IPv6 work through ip6tables, and later the xtables command family that collected IPv4, IPv6, ARP, and Ethernet bridge filtering tools under related interfaces.

The iptables 1.8 series marked the nftables transition period by shipping both legacy xtables commands and nft-backed variants such as iptables-nft, ip6tables-nft, arptables-nft, ebtables-nft, and translation tools. That made iptables both a historic interface and a migration bridge to nftables.

Adoption history

iptables was adopted broadly because it arrived with the Linux kernel's netfilter subsystem and offered a scriptable firewall language that distributions, hosting providers, routers, container stacks, and security appliances could automate. Its save/restore format made rulesets easy to ship in init scripts and configuration management.

The package remains visible in package-manager culture because many Linux systems, compatibility scripts, and container/networking components still know the iptables command vocabulary even when the underlying backend is nftables. Homebrew's package metadata also exposes the full command family for macOS users who need the Linux-compatible tooling.

How it is used

Typical use centers on creating chains and rules for packet filtering, network address translation, port forwarding, connection-state matching, and firewall persistence with iptables-save and iptables-restore. Administrators also use iptables-translate and iptables-restore-translate when moving legacy rule sets toward nftables.

The package is Linux-specific in purpose: on non-Linux systems it is mostly useful for packaging, cross-development, documentation, or compatibility workflows rather than native packet filtering.

Why package nerds care

For package nerds, iptables is one of the canonical examples of a small command-line package whose real meaning comes from the kernel ABI underneath it. Its packaging has to preserve many executable names because shell scripts, orchestration tools, and documentation often reference exact command variants.

It is also a transition fossil: one package contains legacy commands, nft-backed commands, multi-call binaries, and translation helpers, making it a compact map of two generations of Linux firewall administration.

Timeline

  • 1999: Netfilter core design work generalized iptables and the filter, nat, and mangle table model.
  • 2000: Netfilter and iptables work was prepared for inclusion with Linux 2.4.
  • 2001: Linux 2.4 made netfilter/iptables the standard Linux firewall framework.
  • 2018: iptables 1.8 introduced the nft-backed command variants as part of the nftables migration path.
  • 2026: Netfilter news records continued iptables 1.8 maintenance releases.

Related projects

  • iptables is closely related to netfilter kernel hooks, nftables, libnftnl, conntrack-tools, ipset, ulogd, arptables, ebtables, and the older ipchains and ipfwadm systems it replaced.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
arptablesexecutableindexed executableDiscovered from the local executable index.
arptables-nftexecutableindexed executableDiscovered from the local executable index.
arptables-nft-restoreexecutableindexed executableDiscovered from the local executable index.
arptables-nft-saveexecutableindexed executableDiscovered from the local executable index.
arptables-restoreexecutableindexed executableDiscovered from the local executable index.
arptables-saveexecutableindexed executableDiscovered from the local executable index.
arptables-translateexecutableindexed executableDiscovered from the local executable index.
ebtablesexecutableindexed executableDiscovered from the local executable index.
ebtables-nftexecutableindexed executableDiscovered from the local executable index.
ebtables-nft-restoreexecutableindexed executableDiscovered from the local executable index.
ebtables-nft-saveexecutableindexed executableDiscovered from the local executable index.
ebtables-restoreexecutableindexed executableDiscovered from the local executable index.
ebtables-saveexecutableindexed executableDiscovered from the local executable index.
ebtables-translateexecutableindexed executableDiscovered from the local executable index.
ip6tablesexecutableindexed executableDiscovered from the local executable index.
ip6tables-applyexecutableindexed executableDiscovered from the local executable index.
ip6tables-legacyexecutableindexed executableDiscovered from the local executable index.
ip6tables-legacy-restoreexecutableindexed executableDiscovered from the local executable index.
ip6tables-legacy-saveexecutableindexed executableDiscovered from the local executable index.
ip6tables-nftexecutableindexed executableDiscovered from the local executable index.
ip6tables-nft-restoreexecutableindexed executableDiscovered from the local executable index.
ip6tables-nft-saveexecutableindexed executableDiscovered from the local executable index.
ip6tables-restoreexecutableindexed executableDiscovered from the local executable index.
ip6tables-restore-translateexecutableindexed executableDiscovered from the local executable index.
ip6tables-saveexecutableindexed executableDiscovered from the local executable index.
ip6tables-translateexecutableindexed executableDiscovered from the local executable index.
iptablesexecutableindexed executableDiscovered from the local executable index.
iptables-applyexecutableindexed executableDiscovered from the local executable index.
iptables-legacyexecutableindexed executableDiscovered from the local executable index.
iptables-legacy-restoreexecutableindexed executableDiscovered from the local executable index.
iptables-legacy-saveexecutableindexed executableDiscovered from the local executable index.
iptables-nftexecutableindexed executableDiscovered from the local executable index.
iptables-nft-restoreexecutableindexed executableDiscovered from the local executable index.
iptables-nft-saveexecutableindexed executableDiscovered from the local executable index.
iptables-restoreexecutableindexed executableDiscovered from the local executable index.
iptables-restore-translateexecutableindexed executableDiscovered from the local executable index.
iptables-saveexecutableindexed executableDiscovered from the local executable index.
iptables-translateexecutableindexed executableDiscovered from the local executable index.
iptables-xmlexecutableindexed executableDiscovered from the local executable index.
nfbpf_compileexecutableindexed executableDiscovered from the local executable index.
nfnl_osfexecutableindexed executableDiscovered from the local executable index.
xtables-legacy-multiexecutableindexed executableDiscovered from the local executable index.
xtables-monitorexecutableindexed executableDiscovered from the local executable index.
xtables-nft-multiexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version1.8.13
manager updated
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:iptables
Version1.8.13
Package managerHomebrew
Homepagehttps://www.netfilter.org/projects/iptables/index.html
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Debian apt95%

iptables 1.8.11-2

administration tools for packet filtering and NAT

https://www.netfilter.org/

sudo apt install iptables
  • Section: net
  • Architecture: amd64
  • 9 dependencies
  • 3 optional deps
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: iptables from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

libip4tc-dev 1.8.11-2

Development files for libip4tc

https://www.netfilter.org/

sudo apt install libip4tc-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: libip4tc-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

libip4tc2 1.8.11-2

netfilter libip4tc library

https://www.netfilter.org/

sudo apt install libip4tc2
  • Section: libs
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: libip4tc2 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

libip6tc-dev 1.8.11-2

Development files for libip6tc

https://www.netfilter.org/

sudo apt install libip6tc-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: libip6tc-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

libip6tc2 1.8.11-2

netfilter libip6tc library

https://www.netfilter.org/

sudo apt install libip6tc2
  • Section: libs
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: libip6tc2 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

libiptc-dev 1.8.11-2

Common development files for libiptc

https://www.netfilter.org/

sudo apt install libiptc-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 2 dependencies
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: libiptc-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

libxtables-dev 1.8.11-2

netfilter xtables library -- development files

https://www.netfilter.org/

sudo apt install libxtables-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: libxtables-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Debian apt95%

libxtables12 1.8.11-2

netfilter xtables library

https://www.netfilter.org/

sudo apt install libxtables12
  • Section: libs
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Debian stable package indexes · deb.debian.org · Debian stable package indexes: libxtables12 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

iptables

nix profile install nixpkgs#iptables
  • normalized package name match
  • Matched by: Iptables
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ip/iptables/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

iptables 1.8.10-3ubuntu2

administration tools for packet filtering and NAT

https://www.netfilter.org/

sudo apt install iptables
  • Section: net
  • Architecture: amd64
  • 9 dependencies
  • 3 optional deps
  • normalized package name match
  • Matched by: Iptables
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: iptables from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz
Ubuntu apt95%

libip4tc-dev 1.8.10-3ubuntu2

Development files for libip4tc

https://www.netfilter.org/

sudo apt install libip4tc-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: libip4tc-dev from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz
Ubuntu apt95%

libip4tc2 1.8.10-3ubuntu2

netfilter libip4tc library

https://www.netfilter.org/

sudo apt install libip4tc2
  • Section: libs
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: libip4tc2 from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz
Ubuntu apt95%

libip6tc-dev 1.8.10-3ubuntu2

Development files for libip6tc

https://www.netfilter.org/

sudo apt install libip6tc-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: libip6tc-dev from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz
Ubuntu apt95%

libip6tc2 1.8.10-3ubuntu2

netfilter libip6tc library

https://www.netfilter.org/

sudo apt install libip6tc2
  • Section: libs
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: libip6tc2 from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz
Ubuntu apt95%

libiptc-dev 1.8.10-3ubuntu2

Common development files for libiptc

https://www.netfilter.org/

sudo apt install libiptc-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 2 dependencies
  • normalized package name match
  • Matched by: Iptables
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: libiptc-dev from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz
Ubuntu apt95%

libxtables-dev 1.8.10-3ubuntu2

netfilter xtables library -- development files

https://www.netfilter.org/

sudo apt install libxtables-dev
  • Section: libdevel
  • Architecture: amd64
  • Source Package: iptables
  • 1 dependencies
  • normalized package name match
  • Matched by: Iptables
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: libxtables-dev from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation