One of the first things you should do after getting a Linux VPS is set up a firewall to control network traffic and protect against port scanning, brute force attacks, and unauthorized access. UFW (Uncomplicated Firewall) is the default firewall tool on Ubuntu and Debian — easy to use, powerful, and suitable for both beginners and experienced administrators.
UFW stands for Uncomplicated Firewall. It is a frontend for iptables that simplifies firewall rule management. UFW ships with Ubuntu since version 8.04 and is fully supported on Debian.
Why configure a firewall on your VPS:
💡 Tip: Always allow SSH before enabling UFW. If you forget, you will be locked out of your server immediately.
Ubuntu 20.04+ ships with UFW pre-installed but disabled. On Debian you may need to install it:
# Update package list
sudo apt update
# Install UFW (usually pre-installed on Ubuntu)
sudo apt install ufw -y
# Check version
ufw version
Verify UFW is installed but not yet active:
sudo ufw status
# Output: Status: inactive
The key principle for a good firewall is Deny All, Allow Specific — block everything first, then open only what is necessary:
# Deny all incoming (except explicitly allowed)
sudo ufw default deny incoming
# Allow all outgoing (server can communicate outward normally)
sudo ufw default allow outgoing
⚠️ Warning: Never enable UFW before allowing SSH. You will be immediately locked out of your server.
# Allow port 22 (standard SSH)
sudo ufw allow 22/tcp
# Or use the service name
sudo ufw allow ssh
# If using a custom SSH port like 2222
sudo ufw allow 2222/tcp
# HTTP
sudo ufw allow 80/tcp
# HTTPS
sudo ufw allow 443/tcp
# Or allow both HTTP and HTTPS via application profile
sudo ufw allow 'Nginx Full'
sudo ufw allow 'Apache Full'
# Allow ports 8000-8100 for TCP
sudo ufw allow 8000:8100/tcp
# FTP Passive Mode ports
sudo ufw allow 20000:21000/tcp
# Deny MySQL (should not be exposed publicly)
sudo ufw deny 3306/tcp
# Remove an existing allow rule
sudo ufw delete allow 80/tcp
# Allow single IP on all ports
sudo ufw allow from 203.0.113.10
# Allow single IP only on port 22
sudo ufw allow from 203.0.113.10 to any port 22
# Allow entire /24 subnet on port 22
sudo ufw allow from 203.0.113.0/24 to any port 22
# Block a single IP
sudo ufw deny from 198.51.100.45
# Block an entire subnet
sudo ufw deny from 198.51.100.0/24
💡 Tip: For production servers with a static office IP, restrict SSH and DirectAdmin panel access to only your team's IP addresses for maximum security.
The UFW limit command automatically blocks any IP that connects more than 6 times within 30 seconds:
# Enable rate limiting for SSH
sudo ufw limit ssh
# Or specify the port number
sudo ufw limit 22/tcp
When this rule is active, UFW will:
After configuring all your rules, enable UFW:
# Enable UFW (will prompt for confirmation)
sudo ufw enable
# Output:
# Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
# Firewall is active and enabled on system startup
⚠️ Verify before pressing Y: Confirm that SSH is allowed before confirming. Otherwise you will be locked out immediately.
sudo ufw disable
sudo ufw reload
# Basic status check
sudo ufw status
# Rules with numbers (useful for deletion)
sudo ufw status numbered
# Full detailed view
sudo ufw status verbose
Example output of ufw status numbered:
Status: active
To Action From
-- ------ ----
[ 1] 22/tcp ALLOW IN Anywhere
[ 2] 80/tcp ALLOW IN Anywhere
[ 3] 443/tcp ALLOW IN Anywhere
[ 4] 22/tcp (v6) ALLOW IN Anywhere (v6)
[ 5] 80/tcp (v6) ALLOW IN Anywhere (v6)
[ 6] 443/tcp (v6) ALLOW IN Anywhere (v6)
# Delete rule number 3
sudo ufw delete 3
Logging helps you identify blocked connection attempts:
# Enable low logging (blocked packets only)
sudo ufw logging low
# Medium logging (blocked + invalid packets)
sudo ufw logging medium
# Watch logs in real time
sudo tail -f /var/log/ufw.log
# View only blocked entries
sudo grep "BLOCK" /var/log/ufw.log | tail -20
A practical UFW config for a VPS running Nginx + DirectAdmin:
# Start fresh
sudo ufw --force reset
# Default policies
sudo ufw default deny incoming
sudo ufw default allow outgoing
# SSH with rate limiting (critical)
sudo ufw limit 22/tcp
# DirectAdmin panel
sudo ufw allow 2222/tcp
# HTTP / HTTPS
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# FTP (only if needed)
sudo ufw allow 21/tcp
sudo ufw allow 20000:21000/tcp
# Enable logging
sudo ufw logging low
# Enable UFW
sudo ufw enable
# Verify
sudo ufw status numbered
💡 AsiaGB VPS: All Thai VPS and Singapore VPS plans run on Ubuntu/Debian with full root access — you can configure UFW immediately after receiving your VPS.
| Command | Action |
|---|---|
ufw enable | Enable UFW |
ufw disable | Disable UFW temporarily |
ufw status numbered | List all rules with numbers |
ufw allow PORT/tcp | Allow TCP port |
ufw deny PORT/tcp | Block TCP port |
ufw limit ssh | Rate limit SSH port |
ufw allow from IP | Whitelist IP on all ports |
ufw deny from IP | Blacklist IP immediately |
ufw delete NUM | Delete rule by number |
ufw reload | Reload all rules |
ufw reset | Reset all rules to default |
ufw logging low/medium/high | Set logging level |
sudo apt install ufwsudo ufw default deny incoming + allow outgoingsudo ufw allow 22/tcpsudo ufw limit sshsudo ufw enablesudo ufw status verboseConfiguring UFW correctly from the first day you receive your VPS effectively protects against port scanning, brute force attacks, and unauthorized access — it is a foundational security measure every VPS should have.