Type something to search...
How to configure a firewall with UFW on a Linux server?

How to configure a firewall with UFW on a Linux server?

To configure a firewall with UFW on a Linux server, install it with sudo apt install ufw, set the default policies to deny incoming and allow outgoing traffic, allow SSH before enabling the firewall, allow any other services you need (such as ports 80 and 443 for a web server), and then run sudo ufw enable. After that, check your rules with sudo ufw status verbose and adjust them as your server changes.

UFW, short for Uncomplicated Firewall, is a friendly front end for the Linux kernel's packet filtering. It's installed by default on Ubuntu and available on Debian, and it turns what would be long iptables or nftables commands into simple, readable rules. This guide covers everything you need to set up UFW for a typical web server, including IP-specific rules, rate limiting, application profiles, logging, IPv6, and the common Docker pitfall.

What UFW Does

A firewall decides which network connections are allowed to reach your server. Without one, any service listening on a public interface, such as a database, a cache like Redis, or a development server you forgot about, is reachable from the entire internet.

UFW manages the underlying kernel firewall rules for you. On current Ubuntu and Debian releases, it uses the iptables interface, which is backed by nftables under the hood. You don't need to know either to use UFW effectively.

Before You Begin

  • Warning: Misconfiguring a firewall can lock you out of a remote server. Always allow SSH before enabling UFW.
  • Keep your current SSH session open while you work, and test with a second session.
  • Know your provider's web console: It gives you access even if SSH is blocked.
  • Check whether SSH uses a non-standard port: If it does, allow that port instead of 22.

You can see what's currently listening with:

sudo ss -tulpn

Step 1: Install UFW

On Ubuntu, UFW is usually preinstalled. On Debian, or if it's missing:

sudo apt update
sudo apt install ufw

Check its status:

sudo ufw status

A new installation shows Status: inactive.

RHEL, Rocky Linux, and AlmaLinux use firewalld by default. UFW is available through EPEL, but it's usually better to stick with firewalld on those systems rather than running two firewall managers.

Step 2: Set Default Policies

Default policies decide what happens to traffic that doesn't match any rule. The secure baseline for a server is:

sudo ufw default deny incoming
sudo ufw default allow outgoing

This blocks all unsolicited incoming connections while letting your server make outbound connections for updates, APIs, and email.

Step 3: Allow SSH

Do this before enabling the firewall. UFW includes an application profile for OpenSSH:

sudo ufw allow OpenSSH

Or allow the port directly:

sudo ufw allow 22/tcp

If your SSH server listens on a custom port, allow that one instead:

sudo ufw allow 2222/tcp

Step 4: Allow Web Traffic

For a web server, allow HTTP and HTTPS:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

If you use HTTP/3, which runs over QUIC on UDP, also allow UDP 443:

sudo ufw allow 443/udp

Nginx and Apache packages also install UFW application profiles. You can list them:

sudo ufw app list

And use them like this:

sudo ufw allow "Nginx Full"

Nginx Full opens ports 80 and 443. For Apache, the equivalent profile is Apache Full. You can see exactly what a profile opens with sudo ufw app info "Nginx Full".

Step 5: Enable UFW

Double-check your rules before enabling:

sudo ufw show added

Make sure SSH is listed. Then enable the firewall:

sudo ufw enable

UFW warns that the command may disrupt existing SSH connections. Type y to continue. Your current session should stay connected because you allowed SSH.

Now open a second terminal and confirm you can still connect. Then check the full status:

sudo ufw status verbose

You'll see the default policies and every active rule.

Common Rule Examples

Allow a Port From a Specific IP

This is great for admin services. For example, allow SSH only from your office IP:

sudo ufw allow from 203.0.113.10 to any port 22 proto tcp

After confirming it works, you can remove the general SSH rule:

sudo ufw delete allow OpenSSH

Only do this if your IP is static, or you have another way back in.

Allow a Subnet

Allow a private network, such as other servers in the same data center, to reach a database:

sudo ufw allow from 10.0.0.0/24 to any port 3306 proto tcp

Allow on a Specific Interface

If your server has a private network interface like eth1:

sudo ufw allow in on eth1 to any port 6379 proto tcp

Allow a Port Range

sudo ufw allow 6000:6010/tcp

When you use a range, you must specify the protocol.

Deny a Specific IP

sudo ufw deny from 198.51.100.23

UFW evaluates rules in order and stops at the first match, so a deny rule must come before any allow rule that would match the same traffic. Use insert to put it at the top:

sudo ufw insert 1 deny from 198.51.100.23

Reject Instead of Deny

deny silently drops traffic. reject sends back an error, which is friendlier for internal networks but tells scanners the host exists:

sudo ufw reject 25/tcp

Rate Limiting SSH

UFW has built-in rate limiting. The limit rule blocks an IP that attempts six or more connections within 30 seconds:

sudo ufw limit OpenSSH

If you already have an allow OpenSSH rule, delete it afterward so the limit rule is the one that applies. Rate limiting works well alongside key-only SSH authentication and Fail2Ban.

Managing Rules

List Rules With Numbers

sudo ufw status numbered

Delete a Rule by Number

sudo ufw delete 3

Numbers shift after each deletion, so re-run status numbered before deleting another.

Delete a Rule by Specification

sudo ufw delete allow 80/tcp

Add Comments

Comments make rules easier to understand months later:

sudo ufw allow from 203.0.113.10 to any port 22 proto tcp comment 'Office SSH'

Disable or Reset

Temporarily turn the firewall off:

sudo ufw disable

Remove all rules and start over (this also disables UFW):

sudo ufw reset

IPv6

If your server has an IPv6 address, make sure UFW manages IPv6 too. Open /etc/default/ufw and confirm:

IPV6=yes

This is the default on current Ubuntu releases. With it enabled, every rule you add applies to both IPv4 and IPv6, which you'll see as separate (v6) lines in the status output. If IPv6 is disabled in UFW but enabled on the server, your IPv6 address may be left unprotected.

Logging

UFW can log blocked connections, which is useful for spotting scans and troubleshooting:

sudo ufw logging on
sudo ufw logging medium

Levels are low, medium, high, and full. low is usually enough and avoids huge log files. On Ubuntu, logs go to /var/log/ufw.log, or you can view them with:

sudo journalctl -k | grep UFW

UFW and Docker

This is the most common UFW surprise. Docker writes its own iptables rules for published container ports, and those rules are processed before UFW's. That means a container started with -p 8080:80 can be reachable from the internet even if UFW doesn't allow port 8080.

Ways to handle it:

  • Bind published ports to localhost and put a reverse proxy in front:
docker run -d -p 127.0.0.1:8080:80 nginx

In Docker Compose:

services:
  web:
    image: nginx
    ports:
      - "127.0.0.1:8080:80"
  • Don't publish ports you don't need: Containers on the same Docker network can talk to each other without publishing ports.
  • Use the DOCKER-USER chain for advanced filtering. Docker's documentation explains how to add rules there, and community projects like ufw-docker help integrate the two.
  • Use your provider's cloud firewall as an extra layer in front of the server.

Always test from an outside machine to confirm which ports are really reachable:

nmap -Pn your-server-ip

Only scan servers you own or have permission to test.

Example: A Typical Web Server Setup

Here's a complete, sensible configuration for a single web server:

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw limit OpenSSH comment 'SSH with rate limiting'
sudo ufw allow 80/tcp comment 'HTTP'
sudo ufw allow 443/tcp comment 'HTTPS'
sudo ufw allow 443/udp comment 'HTTP/3'
sudo ufw logging low
sudo ufw enable
sudo ufw status verbose

Databases, caches, and admin tools stay unreachable from the internet because they aren't allowed. Keep them bound to 127.0.0.1 as well, so they're protected even if a firewall rule is changed by mistake.


FAQ: UFW Firewall

UFW is a strong host firewall, but it's only one layer. Combine it with SSH key authentication, automatic security updates, Fail2Ban, and secure application configuration.

Not if you allow SSH first. Existing connections usually stay open when you enable UFW, but new connections will be blocked if SSH isn't allowed, so always add the SSH rule before running ufw enable.

Deny silently drops the traffic, so the sender gets no response. Reject sends back an error message, which tells the sender the port is closed. Deny is the common choice for public-facing servers.

Not by default. Docker adds its own iptables rules that bypass UFW for published ports. Bind container ports to 127.0.0.1, avoid publishing unnecessary ports, or use the DOCKER-USER chain.

Run sudo ufw status numbered to see rule numbers, then sudo ufw delete followed by the number. You can also delete a rule by repeating its specification after delete, such as sudo ufw delete allow 80/tcp.

It's possible through EPEL, but those systems ship with firewalld, which is better supported there. Use one firewall manager, not both.

The limit rule allows connections but blocks an IP address that opens six or more connections within 30 seconds. It's commonly used to slow down brute-force attempts on SSH.


Conclusion

UFW makes Linux firewalls approachable. Set the defaults to deny incoming and allow outgoing, allow SSH before enabling anything, open only the ports your services need, and verify everything with ufw status verbose from a second session. From there, IP-specific rules, rate limiting, comments, and logging help you tighten and understand your setup.

Remember the two common gotchas: make sure IPv6 is covered, and be careful with Docker's published ports, which bypass UFW by default. With those in mind, UFW gives you a clean, reliable first line of defence for any Ubuntu or Debian server.

Tags :
Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
How does GDPR affect website security?

How does GDPR affect website security?

GDPR affects website security by turning it from a good habit into a legal obligation. If your website collects personal data from people in the EU (

Dive Deeper