UFW (Uncomplicated Firewall)
UFW (Uncomplicated Firewall) is the default firewall front end on Ubuntu. It manages the kernel's packet filter through short commands such as ufw allow 22/tcp. It is installed but inactive by default, and the default policy denies incoming and allows outgoing connections.
1Rules
ufw allow 443/tcp opens a port, ufw deny blocks one, and ufw limit ssh allows SSH but blocks addresses that connect too often. ufw allow from 203.0.113.5 to any port 22 allows one address only. Application profiles, such as 'OpenSSH', are listed with ufw app list.
2Status and deleting
ufw status verbose shows the policy and rules; ufw status numbered numbers the rules so that ufw delete <number> can remove one.
3Docker and UFW
Docker writes its own iptables rules for published container ports, which are processed before UFW's rules. A port published with docker run -p can therefore be reachable even when UFW does not allow it.
How to turn UFW on without locking yourself out
- Allow SSH first:
sudo ufw allow OpenSSH - Allow the other services you need, for example:
sudo ufw allow 443/tcp - Turn the firewall on:
sudo ufw enable - Check the result:
sudo ufw status verbose
Cautions
- Enabling UFW over SSH without an SSH rule cuts your connection.
- Ports published by Docker containers can bypass UFW rules.
Related articles
- SSH keysHow SSH key authentication works, how to create a key with ssh-keygen, install it on a server and protect it.
- systemd units and systemctlWhat a systemd unit is, the common unit types, and how to start, stop, enable and inspect services with systemctl.
- journalctl and the systemd journalHow to read logs with journalctl, check how much space the journal uses and shrink it safely with --vacuum options.
Sources
- ufw(8) manual page (Ubuntu) manpages.ubuntu.com
- Firewalls (Ubuntu Server documentation) ubuntu.com
Last reviewed: