VPS

How to Set Up UFW Firewall on Linux VPS
to Block Unauthorized Access

📅 August 30, 2026 ⏱ ~12 min read 🏷 VPS, Security, Linux
UFW Firewall setup on Linux VPS to prevent brute force attacks

📋 Table of Contents

  1. What is UFW and why use it?
  2. Installing UFW on Ubuntu/Debian
  3. Setting Default Policies
  4. Allowing and Denying Ports
  5. IP Whitelist and Blacklist
  6. Rate Limiting Against Brute Force
  7. Enabling UFW
  8. Checking Status and Rules
  9. UFW Logging
  10. Web Server Configuration Example
  11. Quick Reference Table
  12. Frequently Asked Questions
  13. Summary

One of the first things you should do after getting a Linux VPS is set up a firewall to control network traffic and protect against port scanning, brute force attacks, and unauthorized access. UFW (Uncomplicated Firewall) is the default firewall tool on Ubuntu and Debian — easy to use, powerful, and suitable for both beginners and experienced administrators.

1. What is UFW and Why Use It?

UFW stands for Uncomplicated Firewall. It is a frontend for iptables that simplifies firewall rule management. UFW ships with Ubuntu since version 8.04 and is fully supported on Debian.

Why configure a firewall on your VPS:

💡 Tip: Always allow SSH before enabling UFW. If you forget, you will be locked out of your server immediately.

2. Installing UFW on Ubuntu/Debian

Ubuntu 20.04+ ships with UFW pre-installed but disabled. On Debian you may need to install it:

# Update package list
sudo apt update

# Install UFW (usually pre-installed on Ubuntu)
sudo apt install ufw -y

# Check version
ufw version

Verify UFW is installed but not yet active:

sudo ufw status
# Output: Status: inactive

3. Setting Default Policies

The key principle for a good firewall is Deny All, Allow Specific — block everything first, then open only what is necessary:

# Deny all incoming (except explicitly allowed)
sudo ufw default deny incoming

# Allow all outgoing (server can communicate outward normally)
sudo ufw default allow outgoing

⚠️ Warning: Never enable UFW before allowing SSH. You will be immediately locked out of your server.

4. Allowing and Denying Ports

Allow SSH (Critical — do this first)

# Allow port 22 (standard SSH)
sudo ufw allow 22/tcp

# Or use the service name
sudo ufw allow ssh

# If using a custom SSH port like 2222
sudo ufw allow 2222/tcp

Allow Web Server Ports

# HTTP
sudo ufw allow 80/tcp

# HTTPS
sudo ufw allow 443/tcp

# Or allow both HTTP and HTTPS via application profile
sudo ufw allow 'Nginx Full'
sudo ufw allow 'Apache Full'

Allow Port Ranges

# Allow ports 8000-8100 for TCP
sudo ufw allow 8000:8100/tcp

# FTP Passive Mode ports
sudo ufw allow 20000:21000/tcp

Deny Ports

# Deny MySQL (should not be exposed publicly)
sudo ufw deny 3306/tcp

# Remove an existing allow rule
sudo ufw delete allow 80/tcp

5. IP Whitelist and Blacklist

Allow a Specific IP

# Allow single IP on all ports
sudo ufw allow from 203.0.113.10

# Allow single IP only on port 22
sudo ufw allow from 203.0.113.10 to any port 22

# Allow entire /24 subnet on port 22
sudo ufw allow from 203.0.113.0/24 to any port 22

Block a Suspicious IP

# Block a single IP
sudo ufw deny from 198.51.100.45

# Block an entire subnet
sudo ufw deny from 198.51.100.0/24

💡 Tip: For production servers with a static office IP, restrict SSH and DirectAdmin panel access to only your team's IP addresses for maximum security.

6. Rate Limiting Against Brute Force

The UFW limit command automatically blocks any IP that connects more than 6 times within 30 seconds:

# Enable rate limiting for SSH
sudo ufw limit ssh

# Or specify the port number
sudo ufw limit 22/tcp

When this rule is active, UFW will:

7. Enabling UFW

After configuring all your rules, enable UFW:

# Enable UFW (will prompt for confirmation)
sudo ufw enable

# Output:
# Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
# Firewall is active and enabled on system startup

⚠️ Verify before pressing Y: Confirm that SSH is allowed before confirming. Otherwise you will be locked out immediately.

Disable UFW Temporarily

sudo ufw disable

Reload UFW After Rule Changes

sudo ufw reload

8. Checking Status and Rules

# Basic status check
sudo ufw status

# Rules with numbers (useful for deletion)
sudo ufw status numbered

# Full detailed view
sudo ufw status verbose

Example output of ufw status numbered:

Status: active

     To                         Action      From
     --                         ------      ----
[ 1] 22/tcp                     ALLOW IN    Anywhere
[ 2] 80/tcp                     ALLOW IN    Anywhere
[ 3] 443/tcp                    ALLOW IN    Anywhere
[ 4] 22/tcp (v6)                ALLOW IN    Anywhere (v6)
[ 5] 80/tcp (v6)                ALLOW IN    Anywhere (v6)
[ 6] 443/tcp (v6)               ALLOW IN    Anywhere (v6)

Delete a Rule by Number

# Delete rule number 3
sudo ufw delete 3

9. UFW Logging

Logging helps you identify blocked connection attempts:

# Enable low logging (blocked packets only)
sudo ufw logging low

# Medium logging (blocked + invalid packets)
sudo ufw logging medium

# Watch logs in real time
sudo tail -f /var/log/ufw.log

# View only blocked entries
sudo grep "BLOCK" /var/log/ufw.log | tail -20

10. Web Server Configuration Example

A practical UFW config for a VPS running Nginx + DirectAdmin:

# Start fresh
sudo ufw --force reset

# Default policies
sudo ufw default deny incoming
sudo ufw default allow outgoing

# SSH with rate limiting (critical)
sudo ufw limit 22/tcp

# DirectAdmin panel
sudo ufw allow 2222/tcp

# HTTP / HTTPS
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

# FTP (only if needed)
sudo ufw allow 21/tcp
sudo ufw allow 20000:21000/tcp

# Enable logging
sudo ufw logging low

# Enable UFW
sudo ufw enable

# Verify
sudo ufw status numbered

💡 AsiaGB VPS: All Thai VPS and Singapore VPS plans run on Ubuntu/Debian with full root access — you can configure UFW immediately after receiving your VPS.

11. UFW Command Quick Reference

CommandAction
ufw enableEnable UFW
ufw disableDisable UFW temporarily
ufw status numberedList all rules with numbers
ufw allow PORT/tcpAllow TCP port
ufw deny PORT/tcpBlock TCP port
ufw limit sshRate limit SSH port
ufw allow from IPWhitelist IP on all ports
ufw deny from IPBlacklist IP immediately
ufw delete NUMDelete rule by number
ufw reloadReload all rules
ufw resetReset all rules to default
ufw logging low/medium/highSet logging level

12. Frequently Asked Questions

What is the difference between UFW and iptables?
UFW is a frontend for iptables that makes firewall management simpler. UFW commands are short and easy to understand while iptables provides more granular control but with more complex syntax. Technically they do the same thing — UFW translates its commands into iptables rules behind the scenes.
Does UFW support IPv6?
Yes. Make sure IPV6=yes is set in /etc/default/ufw (the default). Rules you add will automatically apply to both IPv4 and IPv6. When you run ufw status you will see both IPv4 and (v6) entries for each rule.
I accidentally locked myself out of SSH — what do I do?
Access your VPS through the console or out-of-band access from your VPS provider's control panel. Then run ufw allow 22 or ufw disable to restore access. Prevention: always test rules in a second SSH window before closing the original session.
How does UFW rate limiting work?
UFW rate limiting automatically blocks any IP that makes more than 6 connection attempts within 30 seconds. It provides basic brute force protection and is especially useful for SSH. For more sophisticated protection, combine it with Fail2Ban.
Which ports should I open for a web server?
For a typical web server: port 22 (SSH), 80 (HTTP), and 443 (HTTPS). All other ports should remain closed. If using DirectAdmin, also open port 2222 for the control panel. Never expose database ports (3306, 5432) directly to the internet.
What logging levels does UFW offer?
UFW has 5 logging levels: off (disabled), low (blocked packets only), medium (blocked + invalid), high (all packets), and full (including allowed packets). Most servers use low or medium to keep log files manageable. Logs are stored at /var/log/ufw.log.

✅ Summary: UFW Firewall Setup Checklist for a New VPS

  1. Install UFW: sudo apt install ufw
  2. Set default: sudo ufw default deny incoming + allow outgoing
  3. Allow SSH first: sudo ufw allow 22/tcp
  4. Open required ports: 80, 443, and others as needed
  5. Enable SSH rate limiting: sudo ufw limit ssh
  6. Enable UFW: sudo ufw enable
  7. Verify: sudo ufw status verbose

Configuring UFW correctly from the first day you receive your VPS effectively protects against port scanning, brute force attacks, and unauthorized access — it is a foundational security measure every VPS should have.

Ready for a Secure Linux VPS?

AsiaGB Thai and Singapore VPS — Ubuntu/Debian ready to use, full root access, 99% Uptime, SSD storage.

View All VPS Plans