Setting up UFW - Uncomplicated Firewall

Another line of defense to complete on Linux servers is a functioning firewall. Now if you've ever used IP tables, you'll know they are somewhat complex. This is where ufw comes in to its own as it is a simple front end to the aforementioned IP tables.

Installation

Install is a breeze.

sudo apt-get install ufw

Checking Status

Also very easy.

sudo ufw status or sudo ufw status numbered

I prefer numbered, as it then makes it easier to remove entries you don't want or need.

Status: active

     To                         Action      From
     --                         ------      ----
[ 1] 22/tcp                     ALLOW IN    10.0.0.1                  
[ 2] 10051/tcp                  ALLOW IN    10.0.0.1                  
[ 3] Anywhere                   DENY IN     10.0.0.1                  
[ 4] 22/tcp                     ALLOW IN    172.20.16.0/23            
[ 5] 53/udp                     ALLOW IN    Anywhere                  
[ 6] 53/tcp                     ALLOW IN    Anywhere                  
[ 7] 80/tcp                     ALLOW IN    Anywhere                  
[ 8] 443/tcp                    ALLOW IN    Anywhere                  
[ 9] 5201                       ALLOW IN    Anywhere                  
[10] 10050/tcp                  ALLOW IN    Anywhere

Using UFW with IPv6

UFW works out of the box with IPv6. If you don't use IPv6 yet on your network, it is easy to turn off by default.

sudo vim /etc/default/ufw

Then make sure "IPV6" is set to "no", as follows:

IPV6=no

Save and quit. Restart the firewall with the following commands:

sudo ufw disable sudo ufw enable

Default Setup

I always start a setup with the following:

sudo ufw default deny incoming
sudo ufw default allow outgoing

Pretty obvious this one, allow all outbound communication, deny all incoming!

Allowing Connections

Depending on what your server is doing will obviously impact on what rules you need to allow inbound but for a web server this is how I would play it.

If you need to manage the server over the web because it's hosted, then the simple command will allow ssh generally from any address:

sudo ufw allow ssh

My advice would be not to allow access from the entire internet! Especially if only using password authentication although that is another topic. (SSH keys or certificates are far more secure) If access is required on the internet, it is still preferable to permit only the required public IP ranges. This example command is RFC1918 address space but it is the same for public address space.

sudo ufw allow from 192.168.1.0/24 to any port 22

To allow web traffic is also very easy:

sudo ufw allow http
sudo ufw allow https

Possible Requirements

You may need to open up other ports for example:

sudo ufw allow 22000

Note without specifying a protocol version it allows both TCP and UDP. This i suggest should all be tested and checked you can access all required ports as you run through the configuration.

If you need to make sure it is a specific protocol version only e.g. TCP, you can specify as per:

sudo ufw allow to any port 12345 proto tcp

You can also chain commands to allow from a specific address/range to a specific port:

sudo ufw allow from 192.168.1.1 to any port 12345 proto tcp

Deleting Rules

First get the numbered list as before:

sudo ufw status numbered

Then delete rules by issuing the following command:

sudo ufw delete [number]

Where "[number]" is the number of the rule you need to delete. Check the status numbered list as you go as they change as you delete rules.

Easy!

Turning the Firewall On

This one's simple.

sudo ufw enable

To get your full verbose status of the running firewall

sudo ufw status verbose

To turn it off:

sudo ufw disable

Reset Everything

If, somehow you manage to get it all wrong and you want to start fresh. Then type the following:

sudo ufw reset

Warning

UFW does not work with docker bridge networks by default! It only works with natively installed apps or docker containers using the host network type.

Conclusion

You will have a secured server configured to only the access required. As Alan Partridge would say, "Lovely Stuff".

Leave a comment

Your email address will not be published. Comments are moderated before appearing. We retain your IP address for up to 90 days for moderation, then remove it.