Introduction
In this article, we will discuss the optimal iptables configuration for Surfshark VPN on Debian. iptables is a user-space utility program that allows a system administrator to configure the IP packet filter rules of the Linux kernel firewall, implemented as different Netfilter modules. Surfshark VPN is a popular virtual private network (VPN) service that provides enhanced online security and privacy by encrypting all internet traffic.
Prerequisites
Before we proceed with the iptables configuration, make sure you have the following prerequisites:
- A Debian-based Linux distribution (e.g., Ubuntu, Debian, Mint)
- Root access to the system
- Surfshark VPN client installed and configured
Basic iptables Rules
Let's start by setting up some basic iptables rules:
1. Flush and Zero Counters
Flush all existing rules and zero counters:
sudo iptables -F
sudo iptables -Z
2. Allow Established and Related Connections
Accept established and related connections:
sudo iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Surfshark VPN iptables Configuration
Now, let's configure iptables to work with Surfshark VPN:
1. Allow Surfshark VPN Traffic
Add the following rules to allow Surfshark VPN traffic:
# Surfshark VPN TCP
sudo iptables -A INPUT -p tcp --dport 80 --syn -m state --state NEW -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 --syn -m state --state NEW -j ACCEPT
sudo iptables -A INPUT -p udp --dport 1194 --syn -m state --state NEW -j ACCEPT
# Surfshark VPN UDP
sudo iptables -A INPUT -p udp --dport 80 --syn -m state --state NEW -j ACCEPT
sudo iptables -A INPUT -p udp --dport 443 --syn -m state --state NEW -j ACCEPT
sudo iptables -A INPUT -p udp --dport 1194 --syn -m state --state NEW -j ACCEPT
2. Drop Unwanted Traffic
Drop unwanted traffic:
sudo iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
sudo iptables -A INPUT -p icmp --icmp-type echo-reply -j ACCEPT
sudo iptables -A INPUT -p icmp --icmp-type destination-unreachable -j ACCEPT
sudo iptables -A INPUT -p icmp --icmp-type time-exceeded -j ACCEPT
sudo iptables -A INPUT -p icmp --icmp-type parameter-problem -j ACCEPT
sudo iptables -A INPUT -p icmp --icmp-type router-advertisement -j ACCEPT
sudo iptables -A INPUT -p icmp --icmp-type router-solicit -j ACCEPT
sudo iptables -A INPUT -p icmp --icmp-type mask-request -j ACCEPT
sudo iptables -A INPUT -p all --icmp-match --icmp-type 8 --j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 3 --j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 13 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 14 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 15 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 16 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 17 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 18 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 19 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 20 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 21 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 22 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 23 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 24 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 25 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 26 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 27 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 28 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 29 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 30 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 58 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 59 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 86 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 87 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 88 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 89 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 90 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 91 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 92 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 93 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 94 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 95 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 96 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 97 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 98 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 99 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 100 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 128 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 129 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 130 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 131 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 132 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 133 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 134 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 135 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 136 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 137 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 138 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 139 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 143 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 144 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 145 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 146 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 147 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 148 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 149 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 150 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 151 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 152 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 153 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 154 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 155 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 156 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 157 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 158 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 159 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 160 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 161 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 162 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 163 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 164 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 165 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 166 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 167 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 168 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 169 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 170 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 171 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 172 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 173 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 174 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 175 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 176 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 177 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 178 -j DROP
sudo iptables -A INPUT -p all --icmp-match --icmp-type 179 -j DROP
Save iptables Rules
Save the rules to persist across reboots:
sudo iptables-save > /etc/iptables/rules.v4
sudo ufw disable
sudo ufw limit INPUT INPUT --match-state RELATED,ESTABLISHED 0 0
sudo ufw limit OUTPUT OUTPUT 0 0