KVM VPSKVM VPS

Set Up the UFW Firewall on a Linux VPS

Configure UFW on your Linux VPS: allow SSH before enabling, open your game ports, restrict by IP and check the rules without losing access.

UFW (Uncomplicated Firewall) is the simplest way to filter the ports of a Linux VPS: a few readable commands instead of iptables tables. Set up well, it only lets in what you decided. Set up badly, it locks you out - this guide avoids both.

⚙️ Requirements

  • A Lordhosting Linux VPS (Ubuntu or Debian)
  • Root SSH access or a user with sudo - see connecting over SSH
  • The list of ports to open: SSH, web, game ports
Allow SSH before enabling the firewall

ufw enable immediately applies a deny-incoming policy. With no rule for your SSH port, the next connection is refused and only the panel's VNC console gets you back in.

⚙️ 1. Install and inspect UFW

sudo apt update && sudo apt install ufw -y
sudo ufw status verbose

Status: inactive is normal on a fresh VPS: nothing is filtered yet.

⚙️ 2. Set the default policy

The right baseline: deny everything inbound, allow everything outbound.

sudo ufw default deny incoming
sudo ufw default allow outgoing

These two lines block nothing yet - they describe the policy that applies once enabled.

⚙️ 3. Allow SSH, then your services

Always start with SSH, on its real port if you changed it:

sudo ufw allow 22/tcp          # SSH on the default port
sudo ufw allow 2222/tcp        # if you moved SSH

Then add your services, stating the protocol:

sudo ufw allow 80,443/tcp      # website
sudo ufw allow 25565/tcp       # Minecraft Java
sudo ufw allow 19132/udp       # Minecraft Bedrock
sudo ufw allow 30120/tcp       # FiveM
sudo ufw allow 30120/udp

A port opened on the wrong protocol is a closed port: Minecraft Bedrock and FiveM need UDP.

⚙️ 4. Restrict a port to a single address

Administration services - databases, panels, RCON - have no reason to face the internet:

sudo ufw allow from 203.0.113.42 to any port 3306 proto tcp
sudo ufw allow from 203.0.113.0/24 to any port 25575 proto tcp

Only the given address or network reaches the port; everyone else is refused.

⚙️ 5. Enable and verify

sudo ufw enable
sudo ufw status numbered

Read the list again before closing your session. Typical output:

     To                         Action      From
     --                         ------      ----
[ 1] 22/tcp                     ALLOW IN    Anywhere
[ 2] 80,443/tcp                 ALLOW IN    Anywhere
[ 3] 25565/tcp                  ALLOW IN    Anywhere
[ 4] 3306/tcp                   ALLOW IN    203.0.113.42

Open a second terminal and connect over SSH without closing the first one: that is the only test proving you are not locked out.

Rate-limit SSH attempts

sudo ufw limit 22/tcp refuses an address that opens more than six connections in thirty seconds. It is the cheapest measure against automated scanning.

⚙️ 6. Edit or remove a rule

sudo ufw status numbered        # find the number
sudo ufw delete 3               # remove rule 3
sudo ufw reload                 # reload after editing
sudo ufw disable                # turn off without losing the rules

Numbers shift after each removal: re-read the list between two delete commands.

⚙️ 7. The Docker case

Docker writes its own rules below UFW: a container published with -p 8080:8080 stays reachable even if UFW denies port 8080. Two simple answers:

  • publish on loopback only: -p 127.0.0.1:8080:8080
  • or keep the container on the internal network and expose a reverse proxy

See our guide on installing Docker for the rest of the setup.

⚙️ Ready-to-paste configuration

This script sets up a complete firewall in one go: everything closed inbound, SSH rate-limited, your services open, administration reserved for your address. Fill in the two variables and uncomment the ports you need before pasting it all as root.

#!/usr/bin/env bash
# UFW firewall, ready to run.
set -euo pipefail

MY_IP="203.0.113.42"    # your public address: curl -s ifconfig.me
SSH_PORT="22"           # the real port of your SSH service

apt update && apt install -y ufw
ufw --force reset

# Baseline policy: nothing in, everything out
ufw default deny incoming
ufw default allow outgoing

# SSH, rate-limited against scanning
ufw limit ${SSH_PORT}/tcp comment 'SSH'

# Web
ufw allow 80,443/tcp comment 'HTTP HTTPS'

# Games - uncomment what you actually host
# ufw allow 25565/tcp comment 'Minecraft Java'
# ufw allow 19132/udp comment 'Minecraft Bedrock'
# ufw allow 24454/udp comment 'Simple Voice Chat'
# ufw allow 30120/tcp comment 'FiveM'
# ufw allow 30120/udp comment 'FiveM'
# ufw allow 40120/tcp comment 'txAdmin'
# ufw allow 8211/udp comment 'Palworld'
# ufw allow 27015/udp comment 'Palworld Steam query'

# Administration: never open to the internet
ufw allow from ${MY_IP} to any port 3306 proto tcp comment 'MySQL'
ufw allow from ${MY_IP} to any port 25575 proto tcp comment 'RCON'

ufw --force enable
ufw status numbered

The test that keeps you from being locked out, run without closing your current session:

# From a second terminal, on your own machine
ssh -p 22 user@your-vps 'echo "access confirmed"'

And the day-to-day command cheatsheet:

ufw status numbered        # list rules with their numbers
ufw delete 4               # remove rule 4
ufw reload                 # reload after a change
ufw disable                # turn off without losing the rules

✅ Conclusion

Your VPS now accepts only the ports you opened, SSH is protected against scanning and your admin services are reserved for your own addresses. Continue with the other steps for securing a Linux VPS and keep an eye on network traffic.

Our Linux VPS plans come with full root access and a VNC console in the panel - enough to recover even after an unfortunate firewall rule.

Frequently asked questions

Back to KVM VPS
Was this article helpful?
Welcome Offer

Sign up now and enjoy 10% off on your first order by entering the promo code: WELCOME

Logo LordHostingLordhosting is a SASU with a share capital of €1,000. SIREN 105 383 988 RCS Paris.
Copyright © 2026 LordHosting.