01Get It Running
ufw ships with Ubuntu and is available in most other distributions' repositories. On Debian-based systems it's often installed but inactive; on Fedora or openSUSE you'll install it with dnf or zypper first, though those distros default to firewalld instead. Either way, the workflow is the same: define your rules, then enable.
A working firewall without the iptables headache.
Before enabling, set a safe default. This pair of commands closes everything inbound and allows everything outbound — the right posture for a desktop or a personal server:
sudo ufw default deny incoming
sudo ufw default allow outgoingNow add back only what you actually need. SSH first, so you don't lock yourself out:
sudo ufw allow sshThat's equivalent to allow 22/tcp. If you've moved SSH to a non-standard port — a small but worthwhile hardening step — use the port number directly: sudo ufw allow 5522/tcp.
For a web server, add HTTP and HTTPS:
sudo ufw allow http
sudo ufw allow httpsWhen your rules look right, switch it on:
sudo ufw enable02Check, Adjust, Repeat
See the active ruleset any time with:
sudo ufw status verboseEach rule is numbered. To delete one — say you've torn down a service — use sudo ufw status numbered, then sudo ufw delete 3 (replacing 3 with the relevant number). Clean and surgical.
Rate-limiting is one more rule worth knowing. It drops connections from an IP that attempts six or more connections in thirty seconds — useful against brute-force attempts on SSH:
sudo ufw limit sshThat single line replaces a fiddly iptables recipe most people copy-paste without fully understanding.
ufw limit triggers a block03What ufw Won't Do
ufw is a frontend for iptables (or nftables on newer kernels) — it simplifies rule management, not threat detection. It won't catch malformed packets at the application layer, and it does nothing for encrypted traffic that has already been permitted. For most personal machines and light self-hosting, it's genuinely sufficient. For anything more exposed, pair it with fail2ban or look at proper intrusion-detection tooling.
Ten minutes, six commands, one solid perimeter.
