How to set up a firewall on Linux

Block everything except SSH and the web with UFW on Ubuntu or firewalld on RHEL-based systems, without locking yourself out.

1–2 minutes
Engineer beside power equipment in a server room

A firewall decides which network connections may reach your server. A web server usually needs just three ports open: 22 for SSH, 80 for HTTP and 443 for HTTPS. Everything else should be closed.

Always allow SSH before turning the firewall on. Otherwise the firewall closes your own connection and you need the host’s web console to get back in.

Ubuntu and Debian: UFW

sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

UFW denies all other incoming traffic and allows all outgoing traffic by default. To remove a rule later, list them with numbers and delete by number:

sudo ufw status numbered
sudo ufw delete 3

AlmaLinux, Rocky Linux and Fedora: firewalld

firewalld is usually installed and running already.

sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

--permanent saves the rule; --reload applies saved rules.

SSH on a different port

If you moved SSH to, say, port 2222, open that port instead of the SSH service:

sudo ufw allow 2222/tcp
sudo firewall-cmd --permanent --add-port=2222/tcp

On RHEL-based systems, SELinux also has to allow the new port: sudo semanage port -a -t ssh_port_t -p tcp 2222.

Your host may have a firewall too

Many cloud providers offer a network firewall in their control panel, outside the server. If a port is open on the server but still unreachable, check there as well.

Check from outside

From your own computer, see which ports answer:

nc -zv 203.0.113.10 22 80 443

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.