LochStudios  /  Help Centre  /  VPS & Linux  /  Set up a UFW firewall on Ubuntu

Set up a UFW firewall on Ubuntu

Allow only the ports your LochStudios KVM VPS needs with UFW. Open SSH first, and use the portal console if a rule locks you out.

Updated

UFW (Uncomplicated Firewall) is the usual host firewall on Ubuntu. On a LochStudios KVM VPS you run it yourself. It decides which ports the public internet can reach. Set default deny incoming, allow outgoing, then open only what this server actually runs.

Credentials, the IPv4, and an out-of-band console sit on the server in the portal. The console does not need SSH or UFW from your network. If a rule locks you out, open the console there. Still stuck? Open a support ticket.

This article is for Ubuntu (and Debian, where UFW works the same way). We listen on SSH port 22 unless you changed it.

Before you start

  1. Sign in at the portal, open the VPS service, and keep that page open.
  2. Connect with a sudo user, or root on a fresh box. See Connect to your VPS via SSH from macOS or Linux or from Windows.
  3. Prefer a sudo user for daily work: First steps on a new VPS.

Install UFW if it is missing:

sudo apt update
sudo apt install ufw

Enable UFW without locking yourself out

  1. Check the current status

```bash
sudo ufw status
```

On a fresh VPS this is usually inactive.

  1. Set the defaults (deny incoming, allow outgoing)

```bash
sudo ufw default deny incoming
sudo ufw default allow outgoing
```

UFW already allows loopback. A service that only talks to this machine (local MariaDB, for example) does not need a public rule.

  1. Allow SSH before you enable UFW

We listen on port 22. If you skip this and enable UFW, SSH from your computer will stop.

```bash
sudo ufw allow 22/tcp
```

If you already moved SSH to another port, allow that port instead.

You can also pin SSH to your own IPv4. Use a static address, not a hotel or mobile IP that changes:

```bash
sudo ufw allow from 203.0.113.50 to any port 22 proto tcp
```

Swap in your real IPv4.

  1. Enable UFW

```bash
sudo ufw enable
```

Type y when it asks.

  1. Confirm it is active

```bash
sudo ufw status verbose
```

You should see Status: active and the SSH rule.

Leave an extra terminal session open until you have tested a new SSH login.

Open ports for the services you run

Add a rule only when something on this VPS must accept that traffic from the internet.

Web server (HTTP and HTTPS)

Needed for a site and for Certbot:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Mail on this VPS

Open these only if you installed a mail stack on this machine. Hosted LochStudios Mail and cPanel mail are different products. They do not need these ports on the VPS.

sudo ufw allow 25/tcp
sudo ufw allow 587/tcp
sudo ufw allow 465/tcp
sudo ufw allow 993/tcp
sudo ufw allow 995/tcp

MariaDB or MySQL

If the database is only used by apps on this VPS, do not open 3306. Loopback is already allowed.

If another machine must connect, allow that IPv4 only:

sudo ufw allow from 203.0.113.80 to any port 3306 proto tcp

Do not run sudo ufw allow 3306/tcp unless you mean the whole internet. PostgreSQL is the same idea: no public rule if it is local-only. If you must, pin the source IPv4 on 5432.

DNS

Public DNS for domains with us lives on AtlasDNS (ns1.atlasdns.net.au, ns2.atlasdns.net.au, ns3.atlasdns.net.au). Manage it in the portal under Domains → the domain → DNS. Do not open port 53 on the VPS unless you installed a resolver of your own on purpose.

Game servers

See Open the Right Firewall Ports for Your Game Server.

A custom app port

sudo ufw allow 8080/tcp

Replace 8080 with the port the process actually listens on (sudo ss -tlnp).

View and delete rules

List rules with numbers:

sudo ufw status numbered

Delete by number:

sudo ufw delete 5

Use the number from that list.

Delete by spec:

sudo ufw delete allow 8080/tcp

Allow or deny a specific IPv4

Allow one IPv4 to SSH:

sudo ufw allow from 203.0.113.50 to any port 22 proto tcp

Deny one IPv4:

sudo ufw deny from 203.0.113.99

Allow a prefix to HTTPS:

sudo ufw allow from 203.0.113.0/24 to any port 443 proto tcp

Swap the examples for the real addresses.

Disable UFW while you test

sudo ufw disable

Turn it back on when you are done:

sudo ufw enable

Disabling the firewall is for a short test, not day-to-day.

Common layouts

Website plus SSH:

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

Website, SSH, local MariaDB (no public 3306):

sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

Website plus an app on 8080:

sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 8080/tcp
sudo ufw enable

Logging

Turn logging on:

sudo ufw logging on

Watch the log:

sudo tail -f /var/log/ufw.log

Press Ctrl + C to stop.

See what is listening:

sudo ss -tlnp

Only open ports that appear here and that you intend to publish.

If something goes wrong

You cannot SSH after enabling UFW

  1. Sign in at the portal and open the VPS.
  2. Open the console. That session does not use port 22 from your computer.
  3. Allow SSH and confirm UFW is active:

```bash
sudo ufw allow 22/tcp
sudo ufw status verbose
```

If you changed the SSH port, allow that port instead.

Still locked out? Open a support ticket. Tell us the VPS service and what you changed. Do not send the password in the ticket.

A service is not reachable even though you opened the port

  • Confirm the process is running: sudo systemctl status servicename
  • Confirm it is listening: sudo ss -tlnp
  • Confirm the rule: sudo ufw status numbered
  • Confirm the IPv4 you are hitting is the one on the VPS in the portal

UFW will not enable

sudo systemctl restart ufw
sudo ufw status verbose

If it still will not start, open a support ticket and paste the output of sudo ufw status verbose (no secrets).

What to do next

Need a VPS first? See VPS.

Unsure about a rule? Open a support ticket and we will walk through it with you.


Was this article helpful?

← Back to VPS & Linux