UFW Firewall
UFW (Uncomplicated Firewall) is Ubuntu’s default firewall management tool. It is a simplified frontend for iptables/nftables that makes firewall configuration simple and intuitive.
Basic Operations
Enabling and Disabling
# Enable firewall
sudo ufw enable
# Disable firewall
sudo ufw disable
# Check status
sudo ufw status
# Check detailed status
sudo ufw status verbose
# Check rules with numbers
sudo ufw status numberedIf you are managing a server remotely via SSH, you must allow the SSH port first (sudo ufw allow ssh) before enabling the firewall. Otherwise, you will immediately lose remote access once the firewall is enabled.
Default Policies
# Set default to deny incoming connections
sudo ufw default deny incoming
# Set default to allow outgoing connections
sudo ufw default allow outgoing
# Recommended initial configuration
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enableRule Management
Allow Rules
# Allow a specific port
sudo ufw allow 22 # SSH
sudo ufw allow 80 # HTTP
sudo ufw allow 443 # HTTPS
# Specify protocol
sudo ufw allow 22/tcp
sudo ufw allow 53/udp
# Allow a port range
sudo ufw allow 6000:6007/tcp
# Allow a specific IP address
sudo ufw allow from 192.168.1.100
# Allow a specific subnet
sudo ufw allow from 192.168.1.0/24
# Allow a specific IP to access a specific port
sudo ufw allow from 192.168.1.100 to any port 22
# Allow a specific subnet to access a specific port
sudo ufw allow from 10.0.0.0/8 to any port 3306 proto tcpDeny Rules
# Deny a specific port
sudo ufw deny 23 # Telnet
# Deny a specific IP
sudo ufw deny from 203.0.113.50
# Deny a specific IP from accessing a specific port
sudo ufw deny from 203.0.113.50 to any port 22Reject Rules
Unlike deny, reject sends a rejection message back to the requester:
sudo ufw reject 23
sudo ufw reject from 203.0.113.50Deleting Rules
# Delete by number
sudo ufw status numbered
sudo ufw delete 3
# Delete by rule content
sudo ufw delete allow 80
sudo ufw delete deny from 203.0.113.50
# Reset all rules
sudo ufw resetInserting Rules
Rules are matched in order; you can insert a rule at a specific position:
# Insert a rule at position 1
sudo ufw insert 1 deny from 203.0.113.50Application Profiles
UFW supports application profiles to simplify firewall configuration for common services.
Viewing and Using Application Profiles
# List available application profiles
sudo ufw app list
# View application profile details
sudo ufw app info 'Nginx Full'
# Output:
# Profile: Nginx Full
# Title: Web Server (Nginx, HTTP + HTTPS)
# Description: Small, but very powerful and efficient web server
# Ports:
# 80,443/tcp
# Use an application profile
sudo ufw allow 'Nginx Full'
sudo ufw allow 'OpenSSH'
sudo ufw allow 'Samba'Creating Custom Application Profiles
sudo nano /etc/ufw/applications.d/myapp[MyApp]
title=My Custom Application
description=Custom application on port 8080
ports=8080/tcp
[MyApp Full]
title=My Custom Application (Full)
description=Custom application on ports 8080 and 8443
ports=8080,8443/tcp# Update application list
sudo ufw app update MyApp
# Use the new profile
sudo ufw allow 'MyApp'Common Configuration Scenarios
Web Server
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 'OpenSSH'
sudo ufw allow 'Nginx Full'
# Or
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enableDatabase Server
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 'OpenSSH'
# Only allow the application server to access the database
sudo ufw allow from 10.0.1.10 to any port 3306 proto tcp # MySQL
sudo ufw allow from 10.0.1.10 to any port 5432 proto tcp # PostgreSQL
sudo ufw enableMail Server
sudo ufw allow 'OpenSSH'
sudo ufw allow 25/tcp # SMTP
sudo ufw allow 587/tcp # SMTP (submission)
sudo ufw allow 993/tcp # IMAPS
sudo ufw allow 995/tcp # POP3S
sudo ufw enableDocker Environment
Docker bypasses UFW rules by default. To fix this:
# Edit Docker daemon configuration
sudo nano /etc/docker/daemon.json{
"iptables": false
}# Restart Docker
sudo systemctl restart docker
# Or use UFW DOCKER rules
sudo nano /etc/ufw/after.rulesAdd at the end of the file:
# BEGIN UFW AND DOCKER
*filter
:ufw-user-forward - [ACCEPT]
:DOCKER-USER - [ACCEPT]
-A DOCKER-USER -j RETURN -s 10.0.0.0/8
-A DOCKER-USER -j RETURN -s 172.16.0.0/12
-A DOCKER-USER -j RETURN -s 192.168.0.0/16
-A DOCKER-USER -p udp -m udp --sport 53 -j RETURN
-A DOCKER-USER -p tcp -m tcp --sport 80 -j RETURN
-A DOCKER-USER -p tcp -m tcp --sport 443 -j RETURN
-A DOCKER-USER -j ufw-user-forward
COMMIT
# END UFW AND DOCKERsudo ufw reloadAdvanced Configuration
Rate Limiting
UFW supports connection rate limiting, useful for defending against brute-force attacks:
# Limit SSH connection rate (max 6 connections within 30 seconds)
sudo ufw limit 22/tcp
# Limit a specific port's rate
sudo ufw limit 8080/tcpLogging Configuration
# Enable logging
sudo ufw logging on
# Set log level
sudo ufw logging low # Low (default)
sudo ufw logging medium # Medium
sudo ufw logging high # High
sudo ufw logging full # Full
# Disable logging
sudo ufw logging off
# View firewall logs
sudo tail -f /var/log/ufw.log
journalctl -k | grep UFWIPv6 Support
# Ensure IPv6 is enabled
sudo nano /etc/default/ufw
# Confirm: IPV6=yes
# IPv6 rules
sudo ufw allow from 2001:db8::/32 to any port 22Directly Editing Rule Files
UFW rule files are located in /etc/ufw/:
# User rules
sudo nano /etc/ufw/user.rules # IPv4
sudo nano /etc/ufw/user6.rules # IPv6
# Rules executed before UFW rules
sudo nano /etc/ufw/before.rules
# Rules executed after UFW rules
sudo nano /etc/ufw/after.rulesForwarding Rules
If the server acts as a gateway or router:
# Enable forwarding
sudo nano /etc/ufw/sysctl.conf
# Uncomment: net/ipv4/ip_forward=1
# Add NAT rules
sudo nano /etc/ufw/before.rulesAdd before *filter:
# NAT
*nat
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -s 10.0.0.0/24 -o eth0 -j MASQUERADE
COMMIT# Allow forwarding
sudo ufw route allow in on eth1 out on eth0
sudo ufw reloadGraphical Management
GUFW
# Install GUFW (graphical frontend for UFW)
sudo apt install gufw
# Launch
gufwGUFW provides an intuitive graphical interface supporting:
- Toggling the firewall on/off
- Selecting preset security levels
- Adding and managing rules
- Viewing activity logs
Security Center
Ubuntu 26.04’s Security Center is primarily for security-state visibility and permission prompting controls. Continue to manage firewall rules with the ufw command line or GUFW.
Troubleshooting
# Check if UFW is running
sudo ufw status
# Check actual iptables/nftables rules
sudo iptables -L -n -v
sudo nft list ruleset
# Temporarily disable firewall to troubleshoot network issues
sudo ufw disable
# Re-enable after troubleshooting
sudo ufw enable
# View blocked connections
sudo tail -f /var/log/ufw.log
# Full reset
sudo ufw reset