Linux, Web Server & Database
Configure UFW Firewall
Set up UFW (Uncomplicated Firewall) on your Linux server with rules that match what should actually be public.
The Problem
Your server has no firewall configured at all, or one that's either too permissive (everything open) or too restrictive (blocking traffic you actually need), and you're not confident which ports should genuinely be exposed.
About this problem
UFW is a friendlier front-end over Linux's iptables, and most distros ship with it available but not enabled by default — meaning a freshly provisioned server often has every port reachable unless something else (like a cloud provider's own firewall) is already filtering traffic.
This comes up most on new server setups, or after noticing unexpected services listening on ports that were never intentionally opened.
What's Included
- Auditing which services are actually listening and need to be reachable
- Setting default-deny incoming rules with explicit allows only for what's needed (SSH, HTTP/S, etc.)
- Rate-limiting SSH to reduce brute-force exposure
- Testing rules carefully to avoid locking yourself out
What's NOT Included
- Cloud-provider-level firewall/security group configuration (a separate layer, can be covered too if needed)
- Intrusion detection or prevention beyond basic port filtering (see Fail2Ban service)
- Ongoing rule changes as your services evolve
How It Works
- Check currently listening ports and services to establish what genuinely needs to be reachable.
- Set UFW's default policy to deny incoming and allow outgoing.
- Add explicit allow rules only for required ports (SSH, HTTP, HTTPS, any application-specific ports).
- Enable rate-limiting on SSH to slow down brute-force attempts.
- Enable UFW and verify connectivity to each required service before closing out the session, to avoid an accidental lockout.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- What's the difference between UFW and iptables?
- iptables is the underlying Linux firewall framework; UFW is a simpler command-line front-end over it, designed to make common firewall tasks easier without writing raw iptables rules.
- Will enabling UFW disconnect my SSH session?
- It can, if SSH isn't explicitly allowed before enabling the firewall — that's exactly why the SSH rule is added and verified before UFW is switched on, to avoid a lockout.
- Do I need a firewall if my cloud provider already has one?
- Running both is standard practice (defense in depth) — a provider-level firewall and the server's own firewall rules cover slightly different scenarios and failure modes.
- How do I check which rules UFW currently has?
- ufw status verbose lists all active rules, their direction, and whether the firewall is currently enabled.
- Can UFW block outgoing connections too?
- Yes, UFW can filter outgoing traffic as well as incoming, though most setups focus primarily on locking down incoming connections and leave outgoing more open.
- What happens if I lock myself out with UFW?
- If you have console/VNC access through your hosting provider outside of SSH, you can usually fix the rule directly; without that, it can mean a support ticket or rebuild, which is why testing before finalising matters.