UFW (Uncomplicated Firewall) is the usual host firewall on Ubuntu. On a LochStudios KVM VPS you run it yourself. It decides which ports the public internet can reach. Set default deny incoming, allow outgoing, then open only what this server actually runs.
Credentials, the IPv4, and an out-of-band console sit on the server in the portal. The console does not need SSH or UFW from your network. If a rule locks you out, open the console there. Still stuck? Open a support ticket.
This article is for Ubuntu (and Debian, where UFW works the same way). We listen on SSH port 22 unless you changed it.
Before you start
- Sign in at the portal, open the VPS service, and keep that page open.
- Connect with a sudo user, or
rooton a fresh box. See Connect to your VPS via SSH from macOS or Linux or from Windows. - Prefer a sudo user for daily work: First steps on a new VPS.
Install UFW if it is missing:
sudo apt update
sudo apt install ufw
Enable UFW without locking yourself out
- Check the current status
```bash
sudo ufw status
```
On a fresh VPS this is usually inactive.
- Set the defaults (deny incoming, allow outgoing)
```bash
sudo ufw default deny incoming
sudo ufw default allow outgoing
```
UFW already allows loopback. A service that only talks to this machine (local MariaDB, for example) does not need a public rule.
- Allow SSH before you enable UFW
We listen on port 22. If you skip this and enable UFW, SSH from your computer will stop.
```bash
sudo ufw allow 22/tcp
```
If you already moved SSH to another port, allow that port instead.
You can also pin SSH to your own IPv4. Use a static address, not a hotel or mobile IP that changes:
```bash
sudo ufw allow from 203.0.113.50 to any port 22 proto tcp
```
Swap in your real IPv4.
- Enable UFW
```bash
sudo ufw enable
```
Type y when it asks.
- Confirm it is active
```bash
sudo ufw status verbose
```
You should see Status: active and the SSH rule.
Leave an extra terminal session open until you have tested a new SSH login.
Open ports for the services you run
Add a rule only when something on this VPS must accept that traffic from the internet.
Web server (HTTP and HTTPS)
Needed for a site and for Certbot:
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
Mail on this VPS
Open these only if you installed a mail stack on this machine. Hosted LochStudios Mail and cPanel mail are different products. They do not need these ports on the VPS.
sudo ufw allow 25/tcp
sudo ufw allow 587/tcp
sudo ufw allow 465/tcp
sudo ufw allow 993/tcp
sudo ufw allow 995/tcp
MariaDB or MySQL
If the database is only used by apps on this VPS, do not open 3306. Loopback is already allowed.
If another machine must connect, allow that IPv4 only:
sudo ufw allow from 203.0.113.80 to any port 3306 proto tcp
Do not run sudo ufw allow 3306/tcp unless you mean the whole internet. PostgreSQL is the same idea: no public rule if it is local-only. If you must, pin the source IPv4 on 5432.
DNS
Public DNS for domains with us lives on AtlasDNS (ns1.atlasdns.net.au, ns2.atlasdns.net.au, ns3.atlasdns.net.au). Manage it in the portal under Domains → the domain → DNS. Do not open port 53 on the VPS unless you installed a resolver of your own on purpose.
Game servers
See Open the Right Firewall Ports for Your Game Server.
A custom app port
sudo ufw allow 8080/tcp
Replace 8080 with the port the process actually listens on (sudo ss -tlnp).
View and delete rules
List rules with numbers:
sudo ufw status numbered
Delete by number:
sudo ufw delete 5
Use the number from that list.
Delete by spec:
sudo ufw delete allow 8080/tcp
Allow or deny a specific IPv4
Allow one IPv4 to SSH:
sudo ufw allow from 203.0.113.50 to any port 22 proto tcp
Deny one IPv4:
sudo ufw deny from 203.0.113.99
Allow a prefix to HTTPS:
sudo ufw allow from 203.0.113.0/24 to any port 443 proto tcp
Swap the examples for the real addresses.
Disable UFW while you test
sudo ufw disable
Turn it back on when you are done:
sudo ufw enable
Disabling the firewall is for a short test, not day-to-day.
Common layouts
Website plus SSH:
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
Website, SSH, local MariaDB (no public 3306):
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
Website plus an app on 8080:
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 8080/tcp
sudo ufw enable
Logging
Turn logging on:
sudo ufw logging on
Watch the log:
sudo tail -f /var/log/ufw.log
Press Ctrl + C to stop.
See what is listening:
sudo ss -tlnp
Only open ports that appear here and that you intend to publish.
If something goes wrong
You cannot SSH after enabling UFW
- Sign in at the portal and open the VPS.
- Open the console. That session does not use port 22 from your computer.
- Allow SSH and confirm UFW is active:
```bash
sudo ufw allow 22/tcp
sudo ufw status verbose
```
If you changed the SSH port, allow that port instead.
Still locked out? Open a support ticket. Tell us the VPS service and what you changed. Do not send the password in the ticket.
A service is not reachable even though you opened the port
- Confirm the process is running:
sudo systemctl status servicename - Confirm it is listening:
sudo ss -tlnp - Confirm the rule:
sudo ufw status numbered - Confirm the IPv4 you are hitting is the one on the VPS in the portal
UFW will not enable
sudo systemctl restart ufw
sudo ufw status verbose
If it still will not start, open a support ticket and paste the output of sudo ufw status verbose (no secrets).
What to do next
- Restrict SSH to keys: Secure SSH with key-based authentication
- Patch the OS: First steps on a new VPS and Enable Automatic Security Updates
- Issue TLS on the VPS: Get a Free SSL Certificate with Certbot
- Watch load: Monitor Server Resources
- Broader habits: Keep your website secure
Need a VPS first? See VPS.
Unsure about a rule? Open a support ticket and we will walk through it with you.