A firewall decides which network connections may reach your server. A web server usually needs just three ports open: 22 for SSH, 80 for HTTP and 443 for HTTPS. Everything else should be closed.
Always allow SSH before turning the firewall on. Otherwise the firewall closes your own connection and you need the host’s web console to get back in.
Ubuntu and Debian: UFW
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose
UFW denies all other incoming traffic and allows all outgoing traffic by default. To remove a rule later, list them with numbers and delete by number:
sudo ufw status numbered
sudo ufw delete 3
AlmaLinux, Rocky Linux and Fedora: firewalld
firewalld is usually installed and running already.
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all
--permanent saves the rule; --reload applies saved rules.
SSH on a different port
If you moved SSH to, say, port 2222, open that port instead of the SSH service:
sudo ufw allow 2222/tcp
sudo firewall-cmd --permanent --add-port=2222/tcp
On RHEL-based systems, SELinux also has to allow the new port: sudo semanage port -a -t ssh_port_t -p tcp 2222.
Your host may have a firewall too
Many cloud providers offer a network firewall in their control panel, outside the server. If a port is open on the server but still unreachable, check there as well.
Check from outside
From your own computer, see which ports answer:
nc -zv 203.0.113.10 22 80 443
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

