UFW firewall basics
Kort antwoord
UFW (Uncomplicated Firewall) is a simplified front end for the Linux kernel firewall, installed by default on Ubuntu and available on other distributions. Enable it with sudo ufw enable, allow the services you need, and set a default-deny policy for anything else.
UFW is disabled by default on most installs. Before you enable it, make sure a rule for SSH (or whatever port you use to connect) is in place, otherwise you can lock yourself out of the server.
Basic commands
Check status
sudo ufw statusEnable UFW
This activates UFW immediately and enables it at startup.
sudo ufw enableDisable UFW
sudo ufw disableSet a default policy
Deny incoming traffic by default and allow only what you explicitly permit. Replace "deny" with "allow" and "incoming" with "outgoing" or "routed" as needed.
sudo ufw default deny incomingAllowing services
View available application profiles
sudo ufw app listCheck what an app profile opens
sudo ufw app info 'Nginx HTTPS'Allow a service or port
sudo ufw allow ssh
sudo ufw allow https
sudo ufw allow 443/tcp
sudo ufw allow 'Nginx HTTPS'Securing your connection
Restricting access to known IP addresses cuts down on scanning and brute-force traffic significantly.
Allow one IP address on all ports
sudo ufw allow from [your public IP address]Allow an IP on a specific port only
sudo ufw allow from [your public IP address] to any port 22Allow a whole subnet
sudo ufw allow from 192.168.1.0/24Block instead of allow
Replace "allow" with "deny" in any of the commands above to block an IP address or subnet.
Deleting rules
List rules with numbers
sudo ufw status numberedDelete a rule by number
sudo ufw delete 1Reset UFW entirely
This deletes all rules and disables UFW.
sudo ufw reset