Set Up the UFW Firewall on a Linux VPS
Configure UFW on your Linux VPS: allow SSH before enabling, open your game ports, restrict by IP and check the rules without losing access.
UFW (Uncomplicated Firewall) is the simplest way to filter the ports of a Linux VPS: a few readable commands instead of iptables tables. Set up well, it only lets in what you decided. Set up badly, it locks you out - this guide avoids both.
⚙️ Requirements
- A Lordhosting Linux VPS (Ubuntu or Debian)
- Root SSH access or a user with
sudo- see connecting over SSH - The list of ports to open: SSH, web, game ports
ufw enable immediately applies a deny-incoming policy. With no rule for your SSH port, the next connection is refused and only the panel's VNC console gets you back in.
⚙️ 1. Install and inspect UFW
sudo apt update && sudo apt install ufw -y
sudo ufw status verbose
Status: inactive is normal on a fresh VPS: nothing is filtered yet.
⚙️ 2. Set the default policy
The right baseline: deny everything inbound, allow everything outbound.
sudo ufw default deny incoming
sudo ufw default allow outgoing
These two lines block nothing yet - they describe the policy that applies once enabled.
⚙️ 3. Allow SSH, then your services
Always start with SSH, on its real port if you changed it:
sudo ufw allow 22/tcp # SSH on the default port
sudo ufw allow 2222/tcp # if you moved SSH
Then add your services, stating the protocol:
sudo ufw allow 80,443/tcp # website
sudo ufw allow 25565/tcp # Minecraft Java
sudo ufw allow 19132/udp # Minecraft Bedrock
sudo ufw allow 30120/tcp # FiveM
sudo ufw allow 30120/udp
A port opened on the wrong protocol is a closed port: Minecraft Bedrock and FiveM need UDP.
⚙️ 4. Restrict a port to a single address
Administration services - databases, panels, RCON - have no reason to face the internet:
sudo ufw allow from 203.0.113.42 to any port 3306 proto tcp
sudo ufw allow from 203.0.113.0/24 to any port 25575 proto tcp
Only the given address or network reaches the port; everyone else is refused.
⚙️ 5. Enable and verify
sudo ufw enable
sudo ufw status numbered
Read the list again before closing your session. Typical output:
To Action From
-- ------ ----
[ 1] 22/tcp ALLOW IN Anywhere
[ 2] 80,443/tcp ALLOW IN Anywhere
[ 3] 25565/tcp ALLOW IN Anywhere
[ 4] 3306/tcp ALLOW IN 203.0.113.42
Open a second terminal and connect over SSH without closing the first one: that is the only test proving you are not locked out.
sudo ufw limit 22/tcp refuses an address that opens more than six connections in thirty seconds. It is the cheapest measure against automated scanning.
⚙️ 6. Edit or remove a rule
sudo ufw status numbered # find the number
sudo ufw delete 3 # remove rule 3
sudo ufw reload # reload after editing
sudo ufw disable # turn off without losing the rules
Numbers shift after each removal: re-read the list between two delete commands.
⚙️ 7. The Docker case
Docker writes its own rules below UFW: a container published with -p 8080:8080 stays reachable even if UFW denies port 8080. Two simple answers:
- publish on loopback only:
-p 127.0.0.1:8080:8080 - or keep the container on the internal network and expose a reverse proxy
See our guide on installing Docker for the rest of the setup.
⚙️ Ready-to-paste configuration
This script sets up a complete firewall in one go: everything closed inbound, SSH rate-limited, your services open, administration reserved for your address. Fill in the two variables and uncomment the ports you need before pasting it all as root.
#!/usr/bin/env bash
# UFW firewall, ready to run.
set -euo pipefail
MY_IP="203.0.113.42" # your public address: curl -s ifconfig.me
SSH_PORT="22" # the real port of your SSH service
apt update && apt install -y ufw
ufw --force reset
# Baseline policy: nothing in, everything out
ufw default deny incoming
ufw default allow outgoing
# SSH, rate-limited against scanning
ufw limit ${SSH_PORT}/tcp comment 'SSH'
# Web
ufw allow 80,443/tcp comment 'HTTP HTTPS'
# Games - uncomment what you actually host
# ufw allow 25565/tcp comment 'Minecraft Java'
# ufw allow 19132/udp comment 'Minecraft Bedrock'
# ufw allow 24454/udp comment 'Simple Voice Chat'
# ufw allow 30120/tcp comment 'FiveM'
# ufw allow 30120/udp comment 'FiveM'
# ufw allow 40120/tcp comment 'txAdmin'
# ufw allow 8211/udp comment 'Palworld'
# ufw allow 27015/udp comment 'Palworld Steam query'
# Administration: never open to the internet
ufw allow from ${MY_IP} to any port 3306 proto tcp comment 'MySQL'
ufw allow from ${MY_IP} to any port 25575 proto tcp comment 'RCON'
ufw --force enable
ufw status numbered
The test that keeps you from being locked out, run without closing your current session:
# From a second terminal, on your own machine
ssh -p 22 user@your-vps 'echo "access confirmed"'
And the day-to-day command cheatsheet:
ufw status numbered # list rules with their numbers
ufw delete 4 # remove rule 4
ufw reload # reload after a change
ufw disable # turn off without losing the rules
✅ Conclusion
Your VPS now accepts only the ports you opened, SSH is protected against scanning and your admin services are reserved for your own addresses. Continue with the other steps for securing a Linux VPS and keep an eye on network traffic.
Our Linux VPS plans come with full root access and a VNC console in the panel - enough to recover even after an unfortunate firewall rule.

