If you list your rules now, you will will see there are none, and only the three default chains (INPUT, FORWARD, and OUTPUT) remain. For example, to zero the counters for the 1st rule in the INPUT chain, run this: Now that you know how to reset the iptables packet and byte counters, let's look at the two methods that can be used to delete them. If you want to limit the output to a specific chain (INPUT, OUTPUT, TCP, etc. One of the ways to delete iptables rules is by rule specification. ), you can specify the chain name directly after the -L option. After going through this tutorial, you should be familiar with how to list and delete your iptables firewall rules. ), you can specify the chain name directly after the -S option. To do so, you can run the iptables command with the -D option followed by the rule specification. Both methods provide roughly the same information in different formats.

To list out all of the active iptables rules by specification, run the iptables command with the -S option: As you can see, the output looks just like the commands that were used to create them, without the preceding iptables command.

Instead of messing with cron, there is an EASY way to rerun recurring events — "watch". clever way to update iptables firewall without clearing the counters. If you are interested in collecting and using this information regularly, you would probably want to put this command into a script that recorded the output and stored it somewhere, and execute the script periodically using the cron command.

If you want to clear, or zero, the packet and byte counters for your rules, use the -Z option. There are two different ways to view your active iptables rules: in a table or as a list of rule specifications. That is, any part of the rule that isn't indicated by the previous columns.

Let's look at how to list rules first. To do so, simply use the -L and -v option together. Default setting of iptable is to accept all for all type of connections.

This way you don't create an undefended system when you restore. This could be anything from source and destination ports, to the connection state of the packet. These commands will first list the accounting data and then immediately zero the counters and begin counting again.