Securing Ubuntu Server Traffic with Uncomplicated Firewall (UFW)
Learn how to implement a default-deny network policy on Ubuntu Server using UFW to block unauthorized access while maintaining SSH and web service connectivity.
17 May 2026, 22:17 UTC

Preventing Unauthorized Access with a Default-Deny Policy
Leaving an Ubuntu server with all ports open exposes the system to automated scanners and brute-force attacks. The goal is to implement a "default-deny" posture: blocking all unsolicited incoming traffic while allowing the server to initiate outgoing requests for updates and API calls.
The Uncomplicated Firewall (UFW) acts as a simplified interface for iptables, the kernel-level packet filtering system. Using UFW reduces the risk of syntax errors that can lead to security holes or accidental lockouts.
Prerequisites
- An Ubuntu Server instance (tested on 22.04 LTS and 24.04 LTS).
- User account with
sudoprivileges. - Knowledge of the specific ports your applications require (e.g., 80 for HTTP, 443 for HTTPS).
Configuring the Firewall
Warning: If you are connected via SSH, you must allow SSH traffic before enabling the firewall. Failure to do so will terminate your session and lock you out of the server.
- Set Default Policies: Establish the baseline security posture. This ensures that any traffic not explicitly permitted is dropped.
# Run on the server terminal sudo ufw default deny incoming sudo ufw default allow outgoing - Allow Management Traffic: Open port 22 for SSH. You can use the service name or the port number.
# Using the service name sudo ufw allow ssh - Allow Application Traffic: Open ports for your specific web services. For example, to allow both HTTP and HTTPS:
# Allow HTTP (80) and HTTPS (443) sudo ufw allow http sudo ufw allow https - Enable the Firewall: Activate the ruleset. You will be prompted to confirm that the command may disrupt existing SSH connections.
sudo ufw enable
Verification and Diagnostics
To confirm the firewall is active and the rules are applied in the correct order, use the verbose status command:
sudo ufw status verbose
Expected Output: The output should show Status: active and a list of rules showing ALLOW IN for SSH, HTTP, and HTTPS, while the default policy is listed as deny (incoming).
Comparison: Port-Based vs. Application-Based Rules
UFW allows you to define rules using either raw port numbers or predefined application profiles. Application profiles are managed in /etc/ufw/applications.d/.
| Method | Example Command | Use Case | Risk |
|---|---|---|---|
| Port-Based | sudo ufw allow 8080/tcp |
Custom apps or non-standard ports. | Requires manual tracking of port numbers. |
| App-Profile | sudo ufw allow 'Nginx Full' |
Standard software (Nginx, Apache). | Depends on the app installing the profile correctly. |
Handling Connection Issues
If a service becomes unreachable after enabling UFW, check the system logs to see if the firewall is dropping the packets. UFW logs to /var/log/ufw.log or the system journal.
# Check for blocked packets in the kernel log
sudo grep "[UFW BLOCK]" /var/log/syslog
Rollback and Recovery
If you lose connectivity or need to revert to an open state for troubleshooting, you can disable the firewall. This removes all active filtering rules but preserves the configuration for when it is re-enabled.
# Run via local console or recovery mode if SSH is blocked
sudo ufw disable
Limitations
UFW is a wrapper for iptables (or nftables in newer versions). If other software—such as Docker—manages iptables rules directly, those rules may bypass UFW's logic. Always verify the actual packet flow using iptables -L if you suspect rules are being overridden by container runtimes.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.