How to Install and Configure UFW Firewall on Linux: A Complete Guide

To install and configure UFW firewall on Linux, install the ufw package, set default policies to deny all incoming and outgoing traffic, explicitly allow required services such as SSH with rate limiting, then enable the firewall and verify with ufw status verbose.

The imthenachoman/How-To-Secure-A-Linux-Server repository provides enterprise-grade hardening guidance for Linux systems, with specific instructions for deploying UFW (Uncomplicated Firewall) as a simplified front-end to the kernel's iptables subsystem. According to the source documentation in README.md (lines 1593–1700), UFW abstracts complex packet-filtering rules into intuitive commands while enforcing a strict deny-by-default security posture that minimizes attack surface.

Understanding UFW and the Default-Deny Security Model

UFW operates as a user-friendly interface to the Linux kernel's netfilter framework, translating simple command-line directives into complex iptables rules. The recommended security configuration adopts a deny-by-default stance for both inbound and outbound traffic, meaning the firewall blocks every connection attempt unless explicitly permitted. This model ensures that unexpected services, unauthorized applications, or malicious outbound calls from compromised binaries are automatically dropped without manual intervention.

Installing UFW on Debian and Ubuntu

The installation process retrieves the ufw package from standard distribution repositories. No additional repositories or custom scripts from the project are required.

sudo apt install ufw

Configuring Default Policies

Before activating the firewall, establish restrictive baseline rules that deny all traffic by default. This creates the foundation of the security model documented in the repository.

Set default policies to deny both incoming and outgoing connections:

sudo ufw default deny outgoing comment 'deny all outgoing traffic'
sudo ufw default deny incoming comment 'deny all incoming traffic'

Alternatively, if operational requirements demand unrestricted outbound access while maintaining strict inbound controls, you can modify the outgoing policy:

sudo ufw default allow outgoing comment 'allow all outgoing traffic'

Allowing Essential Services

After establishing default-deny policies, explicitly permit only the specific services required for server operation and administration. The repository emphasizes rate-limiting critical entry points to mitigate automated attacks.

SSH with Rate Limiting

Protect administrative access by allowing incoming SSH connections with automatic rate limiting to thwart brute-force attempts:

sudo ufw limit in ssh comment 'allow SSH connections in'

DNS, NTP, and Web Traffic

Permit fundamental outbound services required for name resolution, time synchronization, and web communications:

sudo ufw allow out 53   comment 'allow DNS calls out'
sudo ufw allow out 123  comment 'allow NTP out'
sudo ufw allow out http comment 'allow HTTP traffic out'
sudo ufw allow out https comment 'allow HTTPS traffic out'

Mail and DHCP Services

For servers requiring email functionality or DHCP client operations, allow the relevant standard ports:

sudo ufw allow out ftp comment 'allow FTP traffic out'
sudo ufw allow out whois comment 'allow whois'
sudo ufw allow out 25  comment 'allow SMTP out'
sudo ufw allow out 587 comment 'allow SMTP out'
sudo ufw allow out 67  comment 'allow DHCP client update'
sudo ufw allow out 68  comment 'allow DHCP client update'

Enabling and Verifying the Firewall

Once all rules are defined, activate the firewall and confirm the configuration. Ensure SSH access is configured before enabling UFW to prevent administrative lockout.

Enable the firewall:

sudo ufw enable

Verify active rules, default policies, and listening interfaces:

sudo ufw status verbose

Summary

  • UFW serves as a simplified front-end to iptables, reducing configuration complexity while maintaining robust stateful packet inspection.
  • The deny-by-default model for both incoming and outgoing traffic minimizes attack surface by requiring explicit permission for every connection type.
  • Installation requires only standard package manager commands (apt install ufw) with no custom scripts from the repository.
  • Rate-limiting SSH access (ufw limit in ssh) provides built-in protection against brute-force authentication attempts.
  • Complete implementation details and security rationales are documented in README.md lines 1593–1700 of the imthenachoman/How-To-Secure-A-Linux-Server repository.

Frequently Asked Questions

What is UFW and how does it differ from iptables?

UFW (Uncomplicated Firewall) is a command-line interface that generates iptables rules behind the scenes. While iptables requires complex syntax for chain management, rule ordering, and state tracking, UFW abstracts these details into simple allow and deny commands, making firewall management accessible without sacrificing the underlying security capabilities of the Linux netfilter framework.

Why should I deny outgoing traffic by default?

Denying outgoing traffic by default implements the principle of least privilege for network communications. According to the repository's security guidelines in README.md, this configuration prevents compromised applications or malicious scripts from establishing unauthorized outbound connections to command-and-control servers or exfiltrating data, effectively containing potential security breaches.

How do I allow additional ports after UFW is enabled?

You can add new rules at any time using the ufw allow command followed by the port number, service name, or protocol specification. For example, to allow PostgreSQL traffic on port 5432, execute sudo ufw allow 5432 comment 'allow PostgreSQL'. These changes apply immediately without requiring a firewall restart or service reload.

Will enabling UFW disconnect my current SSH session?

Existing SSH connections typically remain active when enabling UFW because the connection is already tracked in the kernel's connection state table. However, if you enable UFW before explicitly allowing SSH, any subsequent connection attempts—including reconnecting after a disconnect—will be blocked. Always configure sudo ufw limit in ssh before running sudo ufw enable to prevent lockout.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →