01Get It Running

ufw ships with Ubuntu and is available in most other distributions' repositories. On Debian-based systems it's often installed but inactive; on Fedora or openSUSE you'll install it with dnf or zypper first, though those distros default to firewalld instead. Either way, the workflow is the same: define your rules, then enable.

A working firewall without the iptables headache.

Before enabling, set a safe default. This pair of commands closes everything inbound and allows everything outbound — the right posture for a desktop or a personal server:

sudo ufw default deny incoming
sudo ufw default allow outgoing

Now add back only what you actually need. SSH first, so you don't lock yourself out:

sudo ufw allow ssh

That's equivalent to allow 22/tcp. If you've moved SSH to a non-standard port — a small but worthwhile hardening step — use the port number directly: sudo ufw allow 5522/tcp.

For a web server, add HTTP and HTTPS:

sudo ufw allow http
sudo ufw allow https

When your rules look right, switch it on:

sudo ufw enable

02Check, Adjust, Repeat

See the active ruleset any time with:

sudo ufw status verbose

Each rule is numbered. To delete one — say you've torn down a service — use sudo ufw status numbered, then sudo ufw delete 3 (replacing 3 with the relevant number). Clean and surgical.

Rate-limiting is one more rule worth knowing. It drops connections from an IP that attempts six or more connections in thirty seconds — useful against brute-force attempts on SSH:

sudo ufw limit ssh

That single line replaces a fiddly iptables recipe most people copy-paste without fully understanding.

6 connections in 30 secondsthreshold at which ufw limit triggers a block
22default TCP port for SSH

03What ufw Won't Do

ufw is a frontend for iptables (or nftables on newer kernels) — it simplifies rule management, not threat detection. It won't catch malformed packets at the application layer, and it does nothing for encrypted traffic that has already been permitted. For most personal machines and light self-hosting, it's genuinely sufficient. For anything more exposed, pair it with fail2ban or look at proper intrusion-detection tooling.

Ten minutes, six commands, one solid perimeter.