A firewall decides which network connections may reach your VPS. A sensible default for a web server is: allow SSH, HTTP (80) and HTTPS (443), and block everything else. That way a database or admin tool you install later is not exposed to the internet by accident.
Ubuntu and Debian normally use UFW; AlmaLinux and Rocky Linux use firewalld. Use only one of them.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
The golden rule
Always allow your SSH port before you switch the firewall on. If you changed SSH to a custom port, allow that port, not 22. Keep your current SSH session open while you test.
Ubuntu and Debian: UFW
UFW is installed on Ubuntu but switched off. On Debian, install it first with sudo apt install ufw.
sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw allow OpenSSH # or: sudo ufw allow 2222/tcp for a custom port sudo ufw allow 80/tcp sudo ufw allow 443/tcp sudo ufw enable sudo ufw status verbose
Answer y when warned that the command may disrupt SSH connections. Rules apply to both IPv4 and IPv6 by default.
Useful UFW commands
| Task | Command |
|---|---|
| Rate-limit SSH (blocks an IP making 6+ connections in 30 seconds) | sudo ufw limit OpenSSH |
| Allow one IP to reach a port | sudo ufw allow from 198.51.100.7 to any port 3306 proto tcp |
| List rules with numbers | sudo ufw status numbered |
| Delete rule number 4 | sudo ufw delete 4 |
| See application profiles (e.g. Nginx Full) | sudo ufw app list |
| Turn the firewall off | sudo ufw disable |
AlmaLinux and Rocky Linux: firewalld
firewalld is usually installed and running. If sudo firewall-cmd --state doesn't print running, install and start it:
sudo dnf install -y firewalld sudo systemctl enable --now firewalld
Open the web ports (SSH is already allowed in the default public zone):
sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https # custom SSH port, if you use one sudo firewall-cmd --permanent --add-port=2222/tcp sudo firewall-cmd --reload sudo firewall-cmd --list-all
The --permanent flag saves the rule; --reload makes saved rules active. Without --permanent, a rule only lasts until the next reload or reboot.
Useful firewalld commands
| Task | Command |
|---|---|
| Remove a service you don't use (e.g. the Cockpit web console) | sudo firewall-cmd --permanent --remove-service=cockpit |
| Allow one IP to reach a port | sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7" port port="3306" protocol="tcp" accept' |
| Close a port | sudo firewall-cmd --permanent --remove-port=8080/tcp |
| Show the active zone | sudo firewall-cmd --get-active-zones |
Remember to run sudo firewall-cmd --reload after permanent changes.
Which ports might I need?
| Port | Used for | Open to the world? |
|---|---|---|
| 22 (or your custom port) | SSH | Yes, or only your IPs if they are fixed |
| 80, 443 | Websites (HTTP, HTTPS) | Yes |
| 3306 | MySQL / MariaDB | No. Use an SSH tunnel instead |
| 8443, 8083, 10000 etc. | Control panels | Preferably only your IP |
| 25, 465, 587, 993 | Mail server | Only if you run one |
Check what is listening
sudo ss -tulpn
Anything listening on 0.0.0.0 or [::] is reachable from outside unless the firewall blocks it. Services on 127.0.0.1 are local only.
Important: Docker bypasses the firewall
Ports published by Docker containers (for example -p 8080:80) are opened by Docker's own rules and are reachable even if UFW says they are blocked. Publish internal services on localhost only, such as -p 127.0.0.1:8080:80, and put Nginx in front. See How to Install Docker and Docker Compose on Your VPS.
If you lock yourself out
Use the VPS console to log in and run sudo ufw disable or sudo systemctl stop firewalld, then fix the rules. See What to Do If Your VPS Is Unreachable or You Are Locked Out.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer