The countdown to Elevate 2026 is on. Join us in Chicago, London, or Sydney.

Register here

Partners

Docs

LM Academy

LM Community

Platform

Solutions

Pricing

Resources

Company

Platform
  • Infrastructure
  • Cloud & Multi-Cloud
  • Log Management
  • Edwin AI
Solution
  • Automation
  • Tool Consolidation
  • Reduce MTTR
  • Cost Optimization
Industry
  • Healthcare
  • Financial Services
  • Public Sector
  • MSP
Role
  • CIO
  • ITOps
  • CloudOps
  • AIOps
There is no result.
Try it free

14-day access to the full LogicMonitor platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

3,000+ Integrations

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Cloud Cost Optimization

Optimize cloud spend, maintain performance, and control budgets.

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points to independently validate internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time-to-innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

WebPageTest Web Performance

Test, compare, and optimize website speed, Core Web Vitals, and performance across real devices and global locations.

Learn more
Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Autonomous IT

Predictive, autonomous IT built

for resilience.

Automation

Eliminate operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-rooms by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict resilience compliance requirements.

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Learn more
Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

CONFERENCE

SWORD Day

September 17, 2026

Geneva

WEBINAR

Incident Management Has Outgrown Its Playbook

September 23, 2026

Online

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

2026 The Year of Autonomous IT

NEW

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Read the report
About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Careers

Find job openings and learn about our employee benefits.

Newsroom

Stay current with our latest mentions, press releases, and events.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Security

Purpose-built security for the hybrid observability and AI era.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Sustainability

Our commitment to the environment and the people in it.

The countdown to Elevate 2026 is on. Join us in Chicago, London, or Sydney.

Register here
Try it free

Platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

3,000+ Integrations

WebPageTest Web Performance

Test, compare, and optimize website speed, Core Web Vitals, and performance across real devices and global locations.

Solutions

Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Pricing

Resources

Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

NEW

2026 The Year of Autonomous IT

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Company

About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Careers

Find job openings and learn about our employee benefits.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Newsroom

Stay current with our latest mentions, press releases, and events.

Security

Purpose-built security for the hybrid observability and AI era.

Sustainability

Our commitment to the environment and the people in it.

Partners

Docs

LM Academy

LM Community

Agentic AIOps

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Cloud Cost Optimization

Optimize cloud spend, maintain performance, and control budgets.

Internet Performance Monitoring

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points for independent validation of internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time to innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Logs

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

By Business Outcome

Autonomous IT

Predictive, autonomous IT built for resilience.

Automation

Eliminate repetitive operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and data silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-room by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

By Role

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

By Industry

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict operational resilience compliance requirements.

Resources

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

Upcoming Events

CONFERENCE

SWORD Day

September 17, 2026

WEBINAR

Incident Management Has Outgrown Its Playbook

September 23, 2026

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Platform Help

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

BENEFITS OF IPV6

iptables IPv6: Tutorial, Instructions & Examples

ip6tables is your IPv6 firewall — and it doesn’t configure itself. Learn how to install, create rules, and keep your configuration persistent across reboots.

11–17 minutes
June 24, 2026
Denton Chikura

IN THIS DEEP DIVE

CHAPTERS

    NEWSLETTER

    Subscribe to our newsletter

    Get the latest blogs, whitepapers, eGuides, and more straight into your inbox.

    SHARE

    The quick download:

    ip6tables is your IPv6 firewall. Configure it before your perimeter is wide open

    • ip6tables manages IPv6 firewall rules independently of iptables. A rule in one does not apply to the other, so gaps in your IPv6 rules are a real security risk.

    • ICMPv6 must be explicitly permitted in your rules; blocking it entirely breaks fundamental IPv6 operations, including ping, traceroute, and neighbour discovery.

    • Use 5-tuple pseudocode to define your intent first: source, destination, protocol, port, and action, then translate to ip6tables syntax to reduce costly configuration mistakes.

    • Install iptables-persistent and save rules to /etc/iptables/rules.v6, otherwise your firewall resets to wide open on every reboot.

    ip6tables: iptables for IPv6

    This article is a quick-start guide for ip6tables – the IPv6 version of iptables, covering the basics of installing, configuring, viewing, editing, and persistence. It’s primarily intended for those already familiar with iptables for IPv4. 

    For those unfamiliar with iptables, it is a command-line tool used for firewalling, NAT, and traffic accounting purposes. Policy chains are created to handle these various functions, acting on traffic coming into or going out of the host running it. It is most frequently used to firewall traffic coming into the host, such as permitting anyone on the internet to access a webpage but denying SSH or SQL access to all except for a set of trusted hosts.

    To read the man page for ip6tables you can visit https://linux.die.net/man/8/ip6tables.

    Summary of key concepts

    This article covers the following areas, primarily using Ubuntu OS as a reference in our examples.

    InstallationHow to install the package.
    Creating Rules for a Web server ExampleCreating rules for a web server.
    Persistent ConfigurationHow to ensure that configuration survives reboot.
    OperationsHow to view, edit, delete, and restore rules.
    RecommendationsBest practices and cautions.
    ConclusionWrapping up.

    Installation

    Debian/Ubuntu

    Update the apt cache and install the iptables package, which includes v4 and v6 commands:

    $ sudo apt-get update && sudo apt-get install iptables
    
    Hit:1 https://mirrors.linode.com/ubuntu bionic InRelease
    
    Get:2 https://mirrors.linode.com/ubuntu bionic-updates InRelease [88.7 kB]
    
    Get:3 https://mirrors.linode.com/ubuntu bionic-backports InRelease [74.6 kB]
    
    <snip>
    
    Get:38 https://download.zerotier.com/debian/bionic bionic/main i386 Packages [5,104 B]
    
    Get:39 https://debian.drdteam.org stable/multiverse i386 Packages [5,162 B]
    
    Fetched 17.4 MB in 6s (2,801 kB/s)
    
    Reading package lists... Done
    
    Reading package lists... Done
    
    Building dependency tree
    
    Reading state information... Done
    
    iptables is already the newest version (1.6.1-2ubuntu2).

    After reading this article, you might wish to refer to this community-authored Ubuntu iptables how-to guide at https://help.ubuntu.com/community/IptablesHowTo.

    CentOS

    Installing on CentOS/RPM based systems is a little different. Starting with CentOS 7, iptables is still used, but configuring rules is now performed with firewalld as a frontend/wrapper. To switch back to iptables, you must remove firewalld and install iptables:

    $ sudo yum remove firewalld                                 # remove
    
    $ sudo yum install iptables-services                        # install
    
    $ sudo systemctl start iptables                             # start v4
    
    $ sudo systemctl start ip6tables                            # start v6

    From here, the article uses Ubuntu as the reference, but most of the commands are identical after installing and starting the services. One exception is persistence. Here instead you do this:

    $ sudo service iptables save   # v4: saves /etc/sysconfig/iptables
    
    $ sudo service ip6tables save  # v6: savesto /etc/sysconfig/ip6tables
    
    By default, on reboot, iptables will not be running, so you must enable the iptables service to ensure that it starts on boot (it will load any saved configuration):
    
    $ sudo systemctl enable iptables  # v4: enable service; reboot -> enabled
    
    $ sudo systemctl enable ip6tables # v6: enable service; reboot -> enabled

    Creating rules for a web server example

    Let’s create some ip6tables rules for a hypothetical web server. Note that for IPv6 to work fully, we must ensure certain kinds of ICMPv6 messages are permitted. Here we will permit all ICMPv6 messages, but for further reading on ip6tables rules for specific ICMPv6 message types, please see: https://resources.sei.cmu.edu/tools/downloads/vulnerability-analysis/assets/IPv6/ip6tables_rules.txt.

    ServiceProtocolPort(s)Notes
    Web ServiceTCP80, 443This server needs to permit connections from any source to our web server ports. Web servers listen on TCP ports 80 and 443, so we must permit those.
    ManagementTCP22To manage the web server, we need to gain SSH access on TCP port 22.
    Troubleshooting and other functionsICMPv6N/AFor pings, traceroutes, and other functions, we need to permit ICMP.

    Other requirements

    We must not forget that the machine’s loopback interface is also affected by the ip6tables configuration. The machine must be able to communicate freely over the loopback interface because it is used for process-to-process communication. This is the first rule we will add.

    We must also permit ESTABLISHED and RELATED traffic, which is traffic coming in related to any outbound session initiated from our server and any traffic related to an existing session initiated from the outside. A rule like this is usually entered near the very top of the list because the majority of traffic will usually be processed by it.

    Finally, we will deny ALL other traffic as a security best practice. This is our catch-all term applied at the end.

    5-tuple pseudocode: What are our objectives, in simple terms?

    When familiarizing yourself with iptables syntax, it is very important to consider in simple terms what your objectives are before attempting to compose or enter any commands. This practice helps ensure that rule composition and ordering are correct before making your change; after all, firewall issues could cut off your SSH management session and/or disrupt user traffic in a way that is time-consuming to correct.

    In our case, our objectives are:

    • From SRC ANY to DST loopback then ACCEPT
    • From ESTABLISHED or RELATED then ACCEPT
    • From SRC ANY to DST ICMP then ACCEPT
    • From SRC ANY to DST TCP 22 then ACCEPT
    • From SRC ANY to DST TCP 80 then ACCEPT
    • From SRC ANY to DST TCP 443 then ACCEPT
    • From SRC ANY to DST ANY then DROP

    Entering the configuration

    sudo ip6tables -A INPUT -i lo -j ACCEPT
    
    sudo ip6tables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
    
    sudo ip6tables -A INPUT -p icmp -j ACCEPT
    
    sudo ip6tables -A INPUT -p tcp --dport ssh -j ACCEPT
    
    sudo ip6tables -A INPUT -p tcp --dport http -j ACCEPT
    
    sudo ip6tables -A INPUT -p tcp --dport https -j ACCEPT
    
    sudo ip6tables -A INPUT -j DROP

    Viewing the configuration

    Here we have left out our ICMP rule because we will later show you how to insert this rule in a specific location.

    sudo ip6tables -A INPUT -i lo -j ACCEPT
    
    sudo ip6tables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
    
    sudo ip6tables -A INPUT -p icmp -j ACCEPT
    
    sudo ip6tables -A INPUT -p tcp --dport ssh -j ACCEPT
    
    sudo ip6tables -A INPUT -p tcp --dport http -j ACCEPT
    
    sudo ip6tables -A INPUT -p tcp --dport https -j ACCEPT
    
    sudo ip6tables -A INPUT -j DROP

    Persistent configuration

    We must ensure that ip6tables rules are saved every time after editing and then restored after rebooting. A common way to do this through editing /etc/network/interfaces is to add pre-up and post-down commands or scripts to run. These would call the ip6tables-save and ip6tables-restore commands. Refer to the Ubuntu community how-to linked above if you wish to explore this more advanced method.

    The most elegant solution is to simply use the (Ubuntu) iptables-persistent package. Let’s install it and let it save our rules so that they persist on reboot:

    $ sudo apt-get install iptables-persistent
    
    Reading package lists... Done
    
    Building dependency tree
    
    Reading state information... Done
    
    The following additional packages will be installed:
    
      netfilter-persistent
    
    The following NEW packages will be installed:
    
      iptables-persistent netfilter-persistent
    
    0 upgraded, 2 newly installed, 0 to remove and 203 not upgraded.
    
    Need to get 13.1 kB of archives.
    
    After this operation, 81.9 kB of additional disk space will be used.
    
    Do you want to continue? [Y/n] y

    Follow the prompts, which will ask you if you want to save your IPv4 and IPv6 rules. Generally, you will choose Yes here unless you wish NOT to save them, e.g., if you have misconfigured any rules.

    If you selected Yes and saved both your IPv4 and IPv6 rules at the prompts, they will now persist across a reboot instead of being lost.

    Additional changes

    If you make further changes to your rules, consider whether and when to update the “on-boot” configuration. If your new in-memory rules are not yet fully tested, you may want to avoid updating the on-boot configuration, so that in the event of a major problem with iptables filtering, a reboot will ensure that a known-good state is restored.

    Let’s say you have made a rule change in memory and are certain that you want to save it to the on-boot configuration. Let’s use iptables-persistent to update that configuration. For this, you need to actually become root: sudo alone is not sufficient with the default permissions set by the iptables-persistent package:

    $ sudo su
    
    &lt;depending on your configuration, you may need to enter a password here>
    
    # iptables-save > /etc/iptables/rules.v4
    
    # ip6tables-save > /etc/iptables/rules.v6

    Let’s verify the on-boot configuration; here, only only v6 rules are shown:

    $ cat /etc/iptables/rules.v6
    
    &lt;snip>
    
    &lt;snip>
    
    &lt;snip>
    
    # Generated by ip6tables-save v1.6.1 on Mon Aug  1 20:37:22 2022
    
    *filter
    
    :INPUT ACCEPT [0:0]
    
    :FORWARD ACCEPT [0:0]
    
    :OUTPUT ACCEPT [0:0]
    
    -A INPUT -i lo -j ACCEPT
    
    -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    
    -A INPUT -p icmp -j ACCEPT
    
    -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
    
    -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
    
    -A INPUT -j DROP
    
    COMMIT
    
    # Completed on Mon Aug  1 20:37:22 2022

    Manually save to another location (e.g., backup, version control, creating files for exporting to another system, etc). As an example, we will save to the home directory:

    #
    
    # Save all rules to files in your home directory.
    
    # To view the files, use ‘cat ~/iptables_rules*’.
    
    #
    
    $ sudo iptables-save > ~/iptables_rules_v4
    
    $ sudo ip6tables-save > ~/iptables_rules_v6

    Operations

    View rules

    Run ip6tables with option -L for list and -v for verbose. In this example, there are no rules specified; the default configuration is to ACCEPT.

    $ sudo ip6tables -L -v
    
    Chain INPUT (policy ACCEPT 28M packets, 11G bytes)
    
     pkts bytes target     prot opt in     out     source               destination
    
    Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
    
     pkts bytes target     prot opt in     out     source               destination
    
    Chain OUTPUT (policy ACCEPT 25M packets, 5963M bytes)
    
     pkts bytes target     prot opt in     out     source               destination

    Edit rules

    Earlier in the article, we saw output that was missing our ICMP ACCEPT rule. Let’s see how we can insert this new rule in the correct location. First we get the rule line numbers, like this:

    $ sudo ip6tables -L INPUT -v --line-numbers
    
    Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
    
    num   pkts bytes target     prot opt in     out     source    destination
    
    1        0     0 ACCEPT     all      lo     any     anywhere  anywhere
    
    2       17  5069 ACCEPT     all      any    any     anywhere  anywhere             ctstate RELATED,ESTABLISHED
    
    3        0     0 ACCEPT     tcp      any    any     anywhere  anywhere   tcp dpt:ssh
    
    4        0     0 ACCEPT     tcp      any    any     anywhere  anywhere   tcp dpt:http
    
    5        0     0 ACCEPT     tcp      any    any     anywhere  anywhere   tcp dpt:https
    
    6        8   832 DROP       all      any    any     anywhere  anywhere

    We want to insert our ICMP rule after our RELATED/ESTABLISHED rule on line number 2 (see the first column of output for line numbers).

    To insert our new rule specifically at line number 3, we enter -I for insert into our INPUT chain at line number 3:

    $ sudo ip6tables -I INPUT 3 -p icmp -j ACCEPT

    To verify, we use the same line-numbers command as before and here follow with grep to shorten the output to the ICMP rule plus the line before (-B 1) and the line after (-A 1). You can see that the previous line 3 is now line 4:

    $ sudo ip6tables -L INPUT -v --line-numbers | grep icmp -B 1 -A 1
    
    2       25  7561 ACCEPT     all   any    any   anywhere  anywhere             ctstate RELATED,ESTABLISHED
    
    3        0     0 ACCEPT     icmp  any    any   anywhere  anywhere
    
    4        0     0 ACCEPT     tcp   any    any   anywhere  anywhere   tcp dpt:ssh

    network experience solution

    Do you know if IPv6 network tunneling is slowing down your service?

    Encapsulating IPv4 in IPv6 slows down network performance, but you won’t know the culprit unless you also monitor BGP, DNS and CDN among others.

    Learn More

    Delete Rules

    As an example, let’s delete the line that permits HTTPS access on TCP port 443. After the previous example, this rule is unchanged, except it is line number 6 now. To delete line 6 we do -D for delete, INPUT chain, and in this case we want to target line number 6 – the command to delete looks like this:

    sudo ip6tables -D INPUT 6

    Now let’s enter the full sequence of commands (see comments inline):

    #
    
    # Find the line number to delete:
    
    #
    
    $ sudo ip6tables -L INPUT -v --line-numbers
    
    Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
    
    num   pkts bytes target     prot opt in     out     source               destination
    
    1       42  8475 ACCEPT     all      lo     any     anywhere  anywhere
    
    2       25  7561 ACCEPT     all      any    any     anywhere  anywhere             ctstate RELATED,ESTABLISHED
    
    3        0     0 ACCEPT     icmp     any    any     anywhere  anywhere
    
    4        0     0 ACCEPT     tcp      any    any     anywhere  anywhere tcp dpt:ssh
    
    5        0     0 ACCEPT     tcp      any    any     anywhere  anywhere tcp dpt:http
    
    6        0     0 ACCEPT     tcp      any    any     anywhere  anywhere tcp dpt:https
    
    7      366 37232 DROP       all      any    any     anywhere  anywhere
    
    #
    
    # Delete it - line 6: <...> tcp dpt:https
    
    #
    
    $ sudo ip6tables -D INPUT 6
    
    #
    
    # Verify your change - any/any/tcp dpt:https is now gone.
    
    #
    
    $ sudo ip6tables -L INPUT -v --line-numbers
    
    Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
    
    num   pkts bytes target     prot opt in     out     source   destination
    
    1       42  8475 ACCEPT     all      lo     any     anywhere anywhere
    
    2       25  7561 ACCEPT     all      any    any     anywhere anywhere             ctstate RELATED,ESTABLISHED
    
    3        0     0 ACCEPT     icmp     any    any     anywhere anywhere
    
    4        0     0 ACCEPT     tcp      any    any     anywhere anywhere    tcp dpt:ssh
    
    5        0     0 ACCEPT     tcp      any    any     anywhere anywhere    tcp dpt:http
    
    6      374 38064 DROP       all      any    any     anywhere anywhere

    Flushing

    You may misconfigure your IPv4 or IPv6 rules and need to quickly disable the ip6tables firewalling. For example, if you implement some complex connection tracking or logging, and this adversely impacts user traffic or system stability, you need to recover quickly. The simplest way to do this is to flush all the rules. 

    For example, consider this before state:

    $ sudo ip6tables -L INPUT -v
    
    Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
    
     pkts bytes target     prot opt in     out     source   destination
    
       71 14612 ACCEPT     all      lo     any     anywhere anywhere
    
       15  4295 ACCEPT     all      any    any     anywhere anywhere             ctstate RELATED,ESTABLISHED
    
        0     0 ACCEPT     tcp      any    any     anywhere anywhere      tcp dpt:ssh
    
        0     0 ACCEPT     tcp      any    any     anywhere anywhere      tcp dpt:http
    
        0     0 ACCEPT     tcp      any    any     anywhere anywhere      tcp dpt:https
    
      500 50880 DROP       all      any    any     anywhere anywhere

    Next, we flush the rules:

    #
    
    # Flush all IPv6 rules.
    
    #
    
    $ sudo ip6tables -F
    
    And here’s how it looks after:
    
    #
    
    # Chain is emptied of rules - now the default policy ACCEPT applies.
    
    #
    
    $ sudo ip6tables -L INPUT -v
    
    Chain INPUT (policy ACCEPT 2 packets, 208 bytes)
    
     pkts bytes target     prot opt in     out     source               destination
    
    $

    At this point, the server is wide open to all connections, so it’s imperative that you quickly restore a known-good configuration as soon as possible. See the section on persistence for how best to manage on-boot (known-good) configurations; restoring from here is likely the better option for both test and production environments. 

    Restoring configuration

    You can restore the known-good configuration like this (assuming files saved in /etc/iptables/rules.v[4|6] – adjust your path to suit):

    $ sudo su
    
    &lt;depending on your configuration, you may need to enter a password here>
    
    # iptables-restore &lt; /etc/iptables/rules.v4
    
    # ip6tables-restore &lt; /etc/iptables/rules.v6

    Recommendations

    • Start in a Test Environment: Read the man page for ip6tables, try the examples given, and familiarize yourself in a test environment. 
    • Beware of Losing Access: When modifying iptables rules, whether in an IPv4 or IPv6 environment, you risk cutting off network connectivity if you make a mistake in configuration. It is best to ensure that you make rules persistent only after testing them, or you could disrupt your access to the server and be unable to fix the issue. 
    • Work on Each IP Address Family Independently at First: For example, if you first develop, test, and persist your IPv4 rules, then you know that no matter what changes you make to IPv6 rules, you can still access the server via IPv4.
    • Test a Known-Good Configuration First: If you are transitioning to IPv6 only and want to remove IPv4 addressing from the server, it is recommended that you fully test and persist a known-good ip6tables configuration before doing so.
    • Investigate Remote Access: Many VM hosting providers offer remote console access via a web control panel, so even if you cut off your IP access, you can still access the machine to fix any issues. It is still good practice to exercise extreme caution when making changes to your configuration: It’s a habit you should insist on because you may find yourself in a situation where the server does not have console access or the console is down for maintenance.
    • Use Pseudocode and Intention Statements: Familiarize yourself with the concepts of crafting and composing individual rules and rule chains using pseudocode and “5-tuple’’ intention statements. Prepare iptables/ip6tables configurations in a text editor before applying them on the CLI.

    ‍Conclusion

    You should come away from this article with an understanding of the fundamentals of deploying and working with ip6tables. Hopefully you’re already familiar with iptables (IPv4) and find that not much differs other than the command name. Good luck securing your IPv6 perimeters!

    Stop letting IPv6 tunnels slow down your users

    Get unified visibility into IPv6 tunnels, BGP, DNS, CDNs, and more so you can see exactly where encapsulation is adding latency and fix it fast with LogicMonitor’s AI-powered observability.

    Get a demo

    FAQs

    What is ip6tables and how does it differ from iptables?

    ip6tables is the IPv6-specific version of iptables, a command-line firewall tool for Linux. While iptables manages IPv4 traffic rules, ip6tables handles IPv6 traffic rules independently. The two tools are completely separate — a rule applied to iptables does not automatically apply to ip6tables, and vice versa. Both must be configured individually to provide full network security.

    How do I install ip6tables on Ubuntu?

    On Ubuntu/Debian, run “sudo apt-get update && sudo apt-get install iptables” to install the iptables package, which includes both the IPv4 (iptables) and IPv6 (ip6tables) commands. To make rules survive reboots, also install the iptables-persistent package using “sudo apt-get install iptables-persistent” and follow the prompts to save your current rules.

    Why must I allow ICMPv6 in my ip6tables rules?

    ICMPv6 is essential for core IPv6 functionality, including neighbour discovery, router advertisement, and path MTU discovery. Unlike IPv4, where ICMP is optional for most purposes, IPv6 depends on ICMPv6 for basic network operations. Blocking ICMPv6 entirely will break IPv6 connectivity, including ping and traceroute. It is recommended to at least allow specific ICMPv6 message types needed for your use case.

    How do I make ip6tables rules persist after a reboot?

    Use the iptables-persistent package on Ubuntu/Debian: run “sudo apt-get install iptables-persistent” and save your rules when prompted. This stores rules in /etc/iptables/rules.v6 and restores them automatically on boot. After making subsequent changes, save updated rules with “sudo ip6tables-save > /etc/iptables/rules.v6” (as root). On CentOS, use “sudo service ip6tables save” to persist rules to /etc/sysconfig/ip6tables, and enable the service with “sudo systemctl enable ip6tables”.

    By Denton Chikura

    Technical Writer

    Denton Chikura is a technical writer and longtime observability advocate focused on helping site reliability engineers and engineering teams discover the tools and capabilities that strengthen internet resilience. He works at the intersection of monitoring, performance, and infrastructure to make complex systems more understandable and usable, bridging the gap between deep technical detail and real‑world operations. His goal is to help teams build faster, detect issues earlier, and recover smarter, ultimately making the internet a better, more reliable place for everyone.

    Disclaimer: The views expressed on this blog are those of the author and do not necessarily reflect the views of LogicMonitor or its affiliates.

    © LogicMonitor 2026 | All rights reserved. | All trademarks, trade names, service marks, and logos referenced herein belong to their respective companies.

    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring

    How We Compare

    Datadog

    Dynatrace

    Virtana

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda

    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal

    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center

    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education

    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring


    How We Compare

    Datadog

    Dynatrace

    Virtana

    Zenoss

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda


    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal


    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center


    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education


    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Privacy Policy

    Terms of Use

    Preference Center

    Do Not Sell My Information

    © 2026 LogicMonitor