# How to Install and Configure UFW Firewall on Linux: A Complete Guide

> Learn to install and configure UFW firewall on Linux with our complete guide. Secure your server by setting policies, allowing services, and enabling the firewall. Get started now.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**To install and configure UFW firewall on Linux, install the `ufw` package, set default policies to deny all incoming and outgoing traffic, explicitly allow required services such as SSH with rate limiting, then enable the firewall and verify with `ufw status verbose`.**

The `imthenachoman/How-To-Secure-A-Linux-Server` repository provides enterprise-grade hardening guidance for Linux systems, with specific instructions for deploying **UFW** (Uncomplicated Firewall) as a simplified front-end to the kernel's `iptables` subsystem. According to the source documentation in [`README.md`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main/README.md) (lines 1593–1700), UFW abstracts complex packet-filtering rules into intuitive commands while enforcing a strict deny-by-default security posture that minimizes attack surface.

## Understanding UFW and the Default-Deny Security Model

UFW operates as a user-friendly interface to the Linux kernel's netfilter framework, translating simple command-line directives into complex `iptables` rules. The recommended security configuration adopts a **deny-by-default** stance for both inbound and outbound traffic, meaning the firewall blocks every connection attempt unless explicitly permitted. This model ensures that unexpected services, unauthorized applications, or malicious outbound calls from compromised binaries are automatically dropped without manual intervention.

## Installing UFW on Debian and Ubuntu

The installation process retrieves the `ufw` package from standard distribution repositories. No additional repositories or custom scripts from the project are required.

```bash
sudo apt install ufw

```

## Configuring Default Policies

Before activating the firewall, establish restrictive baseline rules that deny all traffic by default. This creates the foundation of the security model documented in the repository.

Set default policies to deny both incoming and outgoing connections:

```bash
sudo ufw default deny outgoing comment 'deny all outgoing traffic'
sudo ufw default deny incoming comment 'deny all incoming traffic'

```

Alternatively, if operational requirements demand unrestricted outbound access while maintaining strict inbound controls, you can modify the outgoing policy:

```bash
sudo ufw default allow outgoing comment 'allow all outgoing traffic'

```

## Allowing Essential Services

After establishing default-deny policies, explicitly permit only the specific services required for server operation and administration. The repository emphasizes rate-limiting critical entry points to mitigate automated attacks.

### SSH with Rate Limiting

Protect administrative access by allowing incoming SSH connections with automatic rate limiting to thwart brute-force attempts:

```bash
sudo ufw limit in ssh comment 'allow SSH connections in'

```

### DNS, NTP, and Web Traffic

Permit fundamental outbound services required for name resolution, time synchronization, and web communications:

```bash
sudo ufw allow out 53   comment 'allow DNS calls out'
sudo ufw allow out 123  comment 'allow NTP out'
sudo ufw allow out http comment 'allow HTTP traffic out'
sudo ufw allow out https comment 'allow HTTPS traffic out'

```

### Mail and DHCP Services

For servers requiring email functionality or DHCP client operations, allow the relevant standard ports:

```bash
sudo ufw allow out ftp comment 'allow FTP traffic out'
sudo ufw allow out whois comment 'allow whois'
sudo ufw allow out 25  comment 'allow SMTP out'
sudo ufw allow out 587 comment 'allow SMTP out'
sudo ufw allow out 67  comment 'allow DHCP client update'
sudo ufw allow out 68  comment 'allow DHCP client update'

```

## Enabling and Verifying the Firewall

Once all rules are defined, activate the firewall and confirm the configuration. Ensure SSH access is configured before enabling UFW to prevent administrative lockout.

Enable the firewall:

```bash
sudo ufw enable

```

Verify active rules, default policies, and listening interfaces:

```bash
sudo ufw status verbose

```

## Summary

- **UFW** serves as a simplified front-end to `iptables`, reducing configuration complexity while maintaining robust stateful packet inspection.
- The deny-by-default model for both incoming and outgoing traffic minimizes attack surface by requiring explicit permission for every connection type.
- Installation requires only standard package manager commands (`apt install ufw`) with no custom scripts from the repository.
- Rate-limiting SSH access (`ufw limit in ssh`) provides built-in protection against brute-force authentication attempts.
- Complete implementation details and security rationales are documented in [`README.md`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main/README.md) lines 1593–1700 of the `imthenachoman/How-To-Secure-A-Linux-Server` repository.

## Frequently Asked Questions

### What is UFW and how does it differ from iptables?

UFW (Uncomplicated Firewall) is a command-line interface that generates `iptables` rules behind the scenes. While `iptables` requires complex syntax for chain management, rule ordering, and state tracking, UFW abstracts these details into simple `allow` and `deny` commands, making firewall management accessible without sacrificing the underlying security capabilities of the Linux netfilter framework.

### Why should I deny outgoing traffic by default?

Denying outgoing traffic by default implements the principle of least privilege for network communications. According to the repository's security guidelines in [`README.md`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main/README.md), this configuration prevents compromised applications or malicious scripts from establishing unauthorized outbound connections to command-and-control servers or exfiltrating data, effectively containing potential security breaches.

### How do I allow additional ports after UFW is enabled?

You can add new rules at any time using the `ufw allow` command followed by the port number, service name, or protocol specification. For example, to allow PostgreSQL traffic on port 5432, execute `sudo ufw allow 5432 comment 'allow PostgreSQL'`. These changes apply immediately without requiring a firewall restart or service reload.

### Will enabling UFW disconnect my current SSH session?

Existing SSH connections typically remain active when enabling UFW because the connection is already tracked in the kernel's connection state table. However, if you enable UFW before explicitly allowing SSH, any subsequent connection attempts—including reconnecting after a disconnect—will be blocked. Always configure `sudo ufw limit in ssh` before running `sudo ufw enable` to prevent lockout.