Skip to content

UFW Firewall Setup & Hardening

The Uncomplicated Firewall (UFW) is a user-friendly frontend for iptables/nftables designed to make network security intuitive on Linux servers.


Step 1: Check Current Firewall Status

01

Check Current Firewall Status

Diagnostics

Before modifying any rules, inspect the active status of UFW. On fresh Debian and Ubuntu installations, UFW is typically installed but remains disabled by default.

Running with the verbose flag displays default policies, logging levels, and existing rules:

Terminal window
sudo ufw status verbose
❯ View Expected Console Output

Status: inactive


Step 2: Enforce Default Security Posture

02

Enforce Default Deny Posture

Hardening

A foundational rule of network defense is Default Deny.

This configuration guarantees that all unsolicited incoming connection requests are dropped immediately, while allowing all outbound traffic initiated by your server:

Terminal window
# Drop all incoming connections by default
sudo ufw default deny incoming
# Allow all outgoing connections by default
sudo ufw default allow outgoing
❯ View Expected Console Output

Default incoming policy changed to β€˜deny’
(be sure to update your rules accordingly)
Default outgoing policy changed to β€˜allow’
(be sure to update your rules accordingly)


Step 3: Whitelist Essential Ports (SSH, Web)

03

Whitelist Essential Services & SSH

Rule Definition

Caution: Make sure to allow SSH before enabling UFW, otherwise you will lock yourself out of your remote server!

Allow OpenSSH along with HTTP and HTTPS for web hosting:

Terminal window
# Allow SSH on port 22 with comment tag
sudo ufw allow 22/tcp comment 'Allow OpenSSH'
# Allow Web Traffic (HTTP & HTTPS)
sudo ufw allow 80/tcp comment 'Allow HTTP'
sudo ufw allow 443/tcp comment 'Allow HTTPS'
❯ View Expected Console Output

Rules updated
Rules updated (v6)


Step 4: Enable Firewall & Audit Live Rules

04

Enable UFW & Review Numbered Rules

Activation

Commit the configuration to the Linux kernel and enable UFW to start automatically on system reboot:

Terminal window
# Enable UFW
sudo ufw enable
# Verify active numbered rules
sudo ufw status numbered
❯ View Expected Console Output

Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
Firewall is active and enabled on system startup
Status: active


To Action From
β€” ------ ----
[ 1] 22/tcp ALLOW IN Anywhere # Allow OpenSSH
[ 2] 80/tcp ALLOW IN Anywhere # Allow HTTP
[ 3] 443/tcp ALLOW IN Anywhere # Allow HTTPS

Ubuntu terminal showing UFW active with default deny incoming and SSH, HTTP, and HTTPS rules

Figure 1: UFW is enabled with the expected default policy and numbered service rules.

Comments