4 min read Sep 26, 2026

How to Set Up a Firewall on Your VPS with UFW or firewalld

Block everything except the ports you need on your Linux VPS: step-by-step UFW rules for Ubuntu and Debian, firewalld rules for AlmaLinux and Rocky, and how to avoid locking yourself out.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

A firewall decides which network connections may reach your VPS. A sensible default for a web server is: allow SSH, HTTP (80) and HTTPS (443), and block everything else. That way a database or admin tool you install later is not exposed to the internet by accident.

Ubuntu and Debian normally use UFW; AlmaLinux and Rocky Linux use firewalld. Use only one of them.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

The golden rule

Always allow your SSH port before you switch the firewall on. If you changed SSH to a custom port, allow that port, not 22. Keep your current SSH session open while you test.

Ubuntu and Debian: UFW

UFW is installed on Ubuntu but switched off. On Debian, install it first with sudo apt install ufw.

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH        # or: sudo ufw allow 2222/tcp for a custom port
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

Answer y when warned that the command may disrupt SSH connections. Rules apply to both IPv4 and IPv6 by default.

Useful UFW commands

TaskCommand
Rate-limit SSH (blocks an IP making 6+ connections in 30 seconds)sudo ufw limit OpenSSH
Allow one IP to reach a portsudo ufw allow from 198.51.100.7 to any port 3306 proto tcp
List rules with numberssudo ufw status numbered
Delete rule number 4sudo ufw delete 4
See application profiles (e.g. Nginx Full)sudo ufw app list
Turn the firewall offsudo ufw disable

AlmaLinux and Rocky Linux: firewalld

firewalld is usually installed and running. If sudo firewall-cmd --state doesn't print running, install and start it:

sudo dnf install -y firewalld
sudo systemctl enable --now firewalld

Open the web ports (SSH is already allowed in the default public zone):

sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
# custom SSH port, if you use one
sudo firewall-cmd --permanent --add-port=2222/tcp
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

The --permanent flag saves the rule; --reload makes saved rules active. Without --permanent, a rule only lasts until the next reload or reboot.

Useful firewalld commands

TaskCommand
Remove a service you don't use (e.g. the Cockpit web console)sudo firewall-cmd --permanent --remove-service=cockpit
Allow one IP to reach a portsudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7" port port="3306" protocol="tcp" accept'
Close a portsudo firewall-cmd --permanent --remove-port=8080/tcp
Show the active zonesudo firewall-cmd --get-active-zones

Remember to run sudo firewall-cmd --reload after permanent changes.

Which ports might I need?

PortUsed forOpen to the world?
22 (or your custom port)SSHYes, or only your IPs if they are fixed
80, 443Websites (HTTP, HTTPS)Yes
3306MySQL / MariaDBNo. Use an SSH tunnel instead
8443, 8083, 10000 etc.Control panelsPreferably only your IP
25, 465, 587, 993Mail serverOnly if you run one

Check what is listening

sudo ss -tulpn

Anything listening on 0.0.0.0 or [::] is reachable from outside unless the firewall blocks it. Services on 127.0.0.1 are local only.

Important: Docker bypasses the firewall

Ports published by Docker containers (for example -p 8080:80) are opened by Docker's own rules and are reachable even if UFW says they are blocked. Publish internal services on localhost only, such as -p 127.0.0.1:8080:80, and put Nginx in front. See How to Install Docker and Docker Compose on Your VPS.

If you lock yourself out

Use the VPS console to log in and run sudo ufw disable or sudo systemctl stop firewalld, then fix the rules. See What to Do If Your VPS Is Unreachable or You Are Locked Out.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer