Skip to Content

UFW Firewall

UFW (Uncomplicated Firewall) is Ubuntu’s default firewall management tool. It is a simplified frontend for iptables/nftables that makes firewall configuration simple and intuitive.

Basic Operations

Enabling and Disabling

# Enable firewall sudo ufw enable # Disable firewall sudo ufw disable # Check status sudo ufw status # Check detailed status sudo ufw status verbose # Check rules with numbers sudo ufw status numbered
Warning

If you are managing a server remotely via SSH, you must allow the SSH port first (sudo ufw allow ssh) before enabling the firewall. Otherwise, you will immediately lose remote access once the firewall is enabled.

Default Policies

# Set default to deny incoming connections sudo ufw default deny incoming # Set default to allow outgoing connections sudo ufw default allow outgoing # Recommended initial configuration sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw enable

Rule Management

Allow Rules

# Allow a specific port sudo ufw allow 22 # SSH sudo ufw allow 80 # HTTP sudo ufw allow 443 # HTTPS # Specify protocol sudo ufw allow 22/tcp sudo ufw allow 53/udp # Allow a port range sudo ufw allow 6000:6007/tcp # Allow a specific IP address sudo ufw allow from 192.168.1.100 # Allow a specific subnet sudo ufw allow from 192.168.1.0/24 # Allow a specific IP to access a specific port sudo ufw allow from 192.168.1.100 to any port 22 # Allow a specific subnet to access a specific port sudo ufw allow from 10.0.0.0/8 to any port 3306 proto tcp

Deny Rules

# Deny a specific port sudo ufw deny 23 # Telnet # Deny a specific IP sudo ufw deny from 203.0.113.50 # Deny a specific IP from accessing a specific port sudo ufw deny from 203.0.113.50 to any port 22

Reject Rules

Unlike deny, reject sends a rejection message back to the requester:

sudo ufw reject 23 sudo ufw reject from 203.0.113.50

Deleting Rules

# Delete by number sudo ufw status numbered sudo ufw delete 3 # Delete by rule content sudo ufw delete allow 80 sudo ufw delete deny from 203.0.113.50 # Reset all rules sudo ufw reset

Inserting Rules

Rules are matched in order; you can insert a rule at a specific position:

# Insert a rule at position 1 sudo ufw insert 1 deny from 203.0.113.50

Application Profiles

UFW supports application profiles to simplify firewall configuration for common services.

Viewing and Using Application Profiles

# List available application profiles sudo ufw app list # View application profile details sudo ufw app info 'Nginx Full' # Output: # Profile: Nginx Full # Title: Web Server (Nginx, HTTP + HTTPS) # Description: Small, but very powerful and efficient web server # Ports: # 80,443/tcp # Use an application profile sudo ufw allow 'Nginx Full' sudo ufw allow 'OpenSSH' sudo ufw allow 'Samba'

Creating Custom Application Profiles

sudo nano /etc/ufw/applications.d/myapp
[MyApp] title=My Custom Application description=Custom application on port 8080 ports=8080/tcp [MyApp Full] title=My Custom Application (Full) description=Custom application on ports 8080 and 8443 ports=8080,8443/tcp
# Update application list sudo ufw app update MyApp # Use the new profile sudo ufw allow 'MyApp'

Common Configuration Scenarios

Web Server

sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw allow 'OpenSSH' sudo ufw allow 'Nginx Full' # Or sudo ufw allow 80/tcp sudo ufw allow 443/tcp sudo ufw enable

Database Server

sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw allow 'OpenSSH' # Only allow the application server to access the database sudo ufw allow from 10.0.1.10 to any port 3306 proto tcp # MySQL sudo ufw allow from 10.0.1.10 to any port 5432 proto tcp # PostgreSQL sudo ufw enable

Mail Server

sudo ufw allow 'OpenSSH' sudo ufw allow 25/tcp # SMTP sudo ufw allow 587/tcp # SMTP (submission) sudo ufw allow 993/tcp # IMAPS sudo ufw allow 995/tcp # POP3S sudo ufw enable

Docker Environment

Docker bypasses UFW rules by default. To fix this:

# Edit Docker daemon configuration sudo nano /etc/docker/daemon.json
{ "iptables": false }
# Restart Docker sudo systemctl restart docker # Or use UFW DOCKER rules sudo nano /etc/ufw/after.rules

Add at the end of the file:

# BEGIN UFW AND DOCKER *filter :ufw-user-forward - [ACCEPT] :DOCKER-USER - [ACCEPT] -A DOCKER-USER -j RETURN -s 10.0.0.0/8 -A DOCKER-USER -j RETURN -s 172.16.0.0/12 -A DOCKER-USER -j RETURN -s 192.168.0.0/16 -A DOCKER-USER -p udp -m udp --sport 53 -j RETURN -A DOCKER-USER -p tcp -m tcp --sport 80 -j RETURN -A DOCKER-USER -p tcp -m tcp --sport 443 -j RETURN -A DOCKER-USER -j ufw-user-forward COMMIT # END UFW AND DOCKER
sudo ufw reload

Advanced Configuration

Rate Limiting

UFW supports connection rate limiting, useful for defending against brute-force attacks:

# Limit SSH connection rate (max 6 connections within 30 seconds) sudo ufw limit 22/tcp # Limit a specific port's rate sudo ufw limit 8080/tcp

Logging Configuration

# Enable logging sudo ufw logging on # Set log level sudo ufw logging low # Low (default) sudo ufw logging medium # Medium sudo ufw logging high # High sudo ufw logging full # Full # Disable logging sudo ufw logging off # View firewall logs sudo tail -f /var/log/ufw.log journalctl -k | grep UFW

IPv6 Support

# Ensure IPv6 is enabled sudo nano /etc/default/ufw # Confirm: IPV6=yes # IPv6 rules sudo ufw allow from 2001:db8::/32 to any port 22

Directly Editing Rule Files

UFW rule files are located in /etc/ufw/:

# User rules sudo nano /etc/ufw/user.rules # IPv4 sudo nano /etc/ufw/user6.rules # IPv6 # Rules executed before UFW rules sudo nano /etc/ufw/before.rules # Rules executed after UFW rules sudo nano /etc/ufw/after.rules

Forwarding Rules

If the server acts as a gateway or router:

# Enable forwarding sudo nano /etc/ufw/sysctl.conf # Uncomment: net/ipv4/ip_forward=1 # Add NAT rules sudo nano /etc/ufw/before.rules

Add before *filter:

# NAT *nat :POSTROUTING ACCEPT [0:0] -A POSTROUTING -s 10.0.0.0/24 -o eth0 -j MASQUERADE COMMIT
# Allow forwarding sudo ufw route allow in on eth1 out on eth0 sudo ufw reload

Graphical Management

GUFW

# Install GUFW (graphical frontend for UFW) sudo apt install gufw # Launch gufw

GUFW provides an intuitive graphical interface supporting:

  • Toggling the firewall on/off
  • Selecting preset security levels
  • Adding and managing rules
  • Viewing activity logs

Security Center

Ubuntu 26.04’s Security Center is primarily for security-state visibility and permission prompting controls. Continue to manage firewall rules with the ufw command line or GUFW.

Troubleshooting

# Check if UFW is running sudo ufw status # Check actual iptables/nftables rules sudo iptables -L -n -v sudo nft list ruleset # Temporarily disable firewall to troubleshoot network issues sudo ufw disable # Re-enable after troubleshooting sudo ufw enable # View blocked connections sudo tail -f /var/log/ufw.log # Full reset sudo ufw reset
Last updated on