Installation
Install is a breeze.
sudo apt-get install ufw
Checking Status
Also very easy.
sudo ufw status or sudo ufw status numbered
I prefer numbered, as it then makes it easier to remove entries you don't want or need.
Status: active
To Action From
-- ------ ----
[ 1] 22/tcp ALLOW IN 10.0.0.1
[ 2] 10051/tcp ALLOW IN 10.0.0.1
[ 3] Anywhere DENY IN 10.0.0.1
[ 4] 22/tcp ALLOW IN 172.20.16.0/23
[ 5] 53/udp ALLOW IN Anywhere
[ 6] 53/tcp ALLOW IN Anywhere
[ 7] 80/tcp ALLOW IN Anywhere
[ 8] 443/tcp ALLOW IN Anywhere
[ 9] 5201 ALLOW IN Anywhere
[10] 10050/tcp ALLOW IN Anywhere
Using UFW with IPv6
UFW works out of the box with IPv6. If you don't use IPv6 yet on your network, it is easy to turn off by default.
sudo vim /etc/default/ufw
Then make sure "IPV6" is set to "no", as follows:
IPV6=no
Save and quit. Restart the firewall with the following commands:
sudo ufw disable sudo ufw enable
Default Setup
I always start a setup with the following:
sudo ufw default deny incoming
sudo ufw default allow outgoing
Pretty obvious this one, allow all outbound communication, deny all incoming!
Allowing Connections
Depending on what your server is doing will obviously impact on what rules you need to allow inbound but for a web server this is how I would play it.
If you need to manage the server over the web because it's hosted, then the simple command will allow ssh generally from any address:
sudo ufw allow ssh
My advice would be not to allow access from the entire internet! Especially if only using password authentication although that is another topic. (SSH keys or certificates are far more secure) If access is required on the internet, it is still preferable to permit only the required public IP ranges. This example command is RFC1918 address space but it is the same for public address space.
sudo ufw allow from 192.168.1.0/24 to any port 22
To allow web traffic is also very easy:
sudo ufw allow http
sudo ufw allow https
Possible Requirements
You may need to open up other ports for example:
sudo ufw allow 22000
Note without specifying a protocol version it allows both TCP and UDP. This i suggest should all be tested and checked you can access all required ports as you run through the configuration.
If you need to make sure it is a specific protocol version only e.g. TCP, you can specify as per:
sudo ufw allow to any port 12345 proto tcp
You can also chain commands to allow from a specific address/range to a specific port:
sudo ufw allow from 192.168.1.1 to any port 12345 proto tcp
Deleting Rules
First get the numbered list as before:
sudo ufw status numbered
Then delete rules by issuing the following command:
sudo ufw delete [number]
Where "[number]" is the number of the rule you need to delete. Check the status numbered list as you go as they change as you delete rules.
Easy!
Turning the Firewall On
This one's simple.
sudo ufw enable
To get your full verbose status of the running firewall
sudo ufw status verbose
To turn it off:
sudo ufw disable
Reset Everything
If, somehow you manage to get it all wrong and you want to start fresh. Then type the following:
sudo ufw reset
Warning
UFW does not work with docker bridge networks by default! It only works with natively installed apps or docker containers using the host network type.
Conclusion
You will have a secured server configured to only the access required. As Alan Partridge would say, "Lovely Stuff".
Leave a comment
Your email address will not be published. Comments are moderated before appearing. We retain your IP address for up to 90 days for moderation, then remove it.