# FirewallBouncer works well but rules not in iptables list

**URL:** <https://discourse.crowdsec.net/t/firewallbouncer-works-well-but-rules-not-in-iptables-list/1274>\
**Category:** crowdsec\
**Created:** [April 30, 2023, 8:15am UTC](https://discourse.crowdsec.net/t/firewallbouncer-works-well-but-rules-not-in-iptables-list/1274 "2023-04-30T08:15:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cyrille37](https://avatars.discourse-cdn.com/v4/letter/c/90db22/32.png) [@Cyrille37](https://discourse.crowdsec.net/u/Cyrille37)\
**Post date:** [April 30, 2023, 8:15am UTC](https://discourse.crowdsec.net/t/firewallbouncer-works-well-but-rules-not-in-iptables-list/1274/1 "2023-04-30T08:15:21Z")

</div>

Hello

**All crowdsec stuff seems to works fine** because a test remote ip was banned by scenario “crowdsecurity/http-bad-user-agent”, but I do not understand **why I don’t see the IP with iptables** `sudo iptables -L -n -v` ??

```auto
debian@www:~$ sudo cscli decisions list -o raw
INFO[30-04-2023 08:04:17] Patching yaml: '/etc/crowdsec/config.yaml' with '/etc/crowdsec/config.yaml.local' 
id,source,ip,reason,action,country,as,events_count,expiration,simulated,alert_id
164650,crowdsec,Ip:49.12.227.144,crowdsecurity/http-bad-user-agent,ban,DE,24940 Hetzner Online GmbH,2,30m42.752534251s,false,25

```

49.12.227.144 is well banned because a `curl -I https://protectedserver.fr/ -H "User-Agent: OpenVAS"` from it is blocked: `curl: (28) Failed to connect to protectedserver.fr port 443: Connection timed out`.

But I cannot see this IP with `sudo iptables -L -n -v`☹

- crowdsec v1.4.6
- FirewallBouncer-1682760977 v0.0.25
- iptables v1.8.2 (nf\_tables)

Thanks for help, or light 🙂

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [May 4, 2023, 2:38pm UTC](https://discourse.crowdsec.net/t/firewallbouncer-works-well-but-rules-not-in-iptables-list/1274/2 "2023-05-04T14:38:42Z")

</div>

We store all IP’s within an ipset for efficiency. So you will see a line at top of input:

```auto
68545 3477K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set crowdsec-blacklists src

```

That is our rule you can confirm the ips in the ipset by running:

```auto
ipset list crowdsec-blacklists
ipset list crowdsec6-blacklists

```
