# Set up a firewall with ufw

> Turn on ufw without locking yourself out, open only the ports you use, and check the rules, on Ubuntu 24.04 or Debian 12.

Source: https://vpsnine.com/help/firewall-with-ufw · Updated: 2026-10-10

ufw, the "uncomplicated firewall", is a friendly front end to the Linux firewall. The policy we recommend is simple: block everything coming in, allow everything going out, then open the handful of ports you actually use.

The one way to get this wrong is to turn the firewall on before allowing SSH. So we'll do it in the right order.

## Install it

Ubuntu 24.04 has ufw already, switched off. Debian 12 doesn't have it:

```bash
apt update
apt install -y ufw
```

Make sure it's off before you start:

```bash
ufw status
```

That should say `Status: inactive`.

## Allow SSH, then switch it on

```bash
ufw allow OpenSSH
```

`OpenSSH` is a profile for port 22. If you moved SSH to another port, allow that instead, for example `ufw allow 2222/tcp`.

Then set the defaults and turn it on:

```bash
ufw default deny incoming
ufw default allow outgoing
ufw enable
```

ufw warns that this may disrupt SSH connections. You've allowed SSH, so answer `y`. Your session stays up.

Check it:

```bash
ufw status verbose
```

You should see `Status: active`, the two default policies, and `OpenSSH ALLOW IN Anywhere`, plus the same line again with `(v6)`. ufw covers IPv6 as well as IPv4 out of the box.

Then open a second terminal and log in again. It's the only real proof that new SSH sessions get through.

## Opening more ports

Open only what you run. A few common ones:

```bash
ufw allow 'Nginx Full'          # HTTP and HTTPS, once nginx is installed
ufw allow 51820/udp             # WireGuard
ufw allow from 203.0.113.0/24 to any port 5432 proto tcp   # PostgreSQL, from one network only
```

`ufw app list` shows which profiles your installed packages provide.

You can also rate-limit SSH. With this rule instead of the plain one, ufw refuses an address that opens six or more connections in 30 seconds:

```bash
ufw limit OpenSSH
```

It takes the edge off, but for proper brute-force protection add [fail2ban](https://vpsnine.com/help/fail2ban) too.

To remove a rule, list them with numbers and delete by number:

```bash
ufw status numbered
ufw delete 3
```

The numbers shift after every delete, so list them again before the next one.

## The Docker gotcha

Ports published by Docker go straight past ufw. A container started with `-p 8080:80` is reachable from the internet, and `ufw status` won't mention port 8080 at all. [Install Docker](https://vpsnine.com/help/install-docker) shows how to bind containers to localhost instead.

## If you lock yourself out

You can fix it from the [serial console](https://vpsnine.com/help/serial-console), if you've set a password to log in there with. Log in and run:

```bash
ufw allow OpenSSH
```

Or switch the firewall off with `ufw disable` while you sort out the rules.
