UFW Firewall Setup & Hardening
The Uncomplicated Firewall (UFW) is a user-friendly frontend for iptables/nftables designed to make network security intuitive on Linux servers.
Step 1: Check Current Firewall Status
Check Current Firewall Status
DiagnosticsBefore modifying any rules, inspect the active status of UFW. On fresh Debian and Ubuntu installations, UFW is typically installed but remains disabled by default.
Running with the verbose flag displays default policies, logging levels, and existing rules:
sudo ufw status verboseβ― View Expected Console Output
Status: inactive
Step 2: Enforce Default Security Posture
Enforce Default Deny Posture
HardeningA foundational rule of network defense is Default Deny.
This configuration guarantees that all unsolicited incoming connection requests are dropped immediately, while allowing all outbound traffic initiated by your server:
# Drop all incoming connections by defaultsudo ufw default deny incoming
# Allow all outgoing connections by defaultsudo ufw default allow outgoingβ― View Expected Console Output
Default incoming policy changed to βdenyβ
(be sure to update your rules accordingly)
Default outgoing policy changed to βallowβ
(be sure to update your rules accordingly)
Step 3: Whitelist Essential Ports (SSH, Web)
Whitelist Essential Services & SSH
Rule DefinitionCaution: Make sure to allow SSH before enabling UFW, otherwise you will lock yourself out of your remote server!
Allow OpenSSH along with HTTP and HTTPS for web hosting:
# Allow SSH on port 22 with comment tagsudo ufw allow 22/tcp comment 'Allow OpenSSH'
# Allow Web Traffic (HTTP & HTTPS)sudo ufw allow 80/tcp comment 'Allow HTTP'sudo ufw allow 443/tcp comment 'Allow HTTPS'β― View Expected Console Output
Rules updated
Rules updated (v6)
Step 4: Enable Firewall & Audit Live Rules
Enable UFW & Review Numbered Rules
ActivationCommit the configuration to the Linux kernel and enable UFW to start automatically on system reboot:
# Enable UFWsudo ufw enable
# Verify active numbered rulessudo ufw status numberedβ― View Expected Console Output
Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
Firewall is active and enabled on system startup
Status: active
To Action From
β ------ ----
[ 1] 22/tcp ALLOW IN Anywhere # Allow OpenSSH
[ 2] 80/tcp ALLOW IN Anywhere # Allow HTTP
[ 3] 443/tcp ALLOW IN Anywhere # Allow HTTPS

Figure 1: UFW is enabled with the expected default policy and numbered service rules.