How to Set Up a Firewall with UFW on Ubuntu 24.04 (Step-by-Step Guide)

 Quick Summary (AEO Answer):

To set up a firewall with UFW (Uncomplicated Firewall) on Ubuntu 24.04, install UFW using sudo apt install ufw, set default policies (deny incoming, allow outgoing) using sudo ufw default deny incoming and sudo ufw default allow outgoing, allow necessary ports like SSH (sudo ufw allow ssh), and finally enable the firewall with sudo ufw enable.

Securing your Linux server is the most crucial step after a fresh OS installation. If you are running Ubuntu 24.04, configuring a firewall should be your top priority to protect against unauthorized access and cyber threats.

In this comprehensive guide, you will learn how to install, configure, and manage a firewall using UFW (Uncomplicated Firewall) with best security practices.

Prerequisites

Before you begin, ensure you have:

An Ubuntu 24.04 server or VPS.

A user account with sudo administrative privileges.

Terminal/SSH access to your server.

Step 1: Install UFW on Ubuntu 24.04

Most Ubuntu installations come with UFW pre-installed. However, if it is missing on your server, you can easily install it using the default APT package manager.

Run the following commands in your terminal:sudo apt update

sudo apt install ufw -y

To verify the installation status, run:sudo ufw status

Note: By default, the status will show as inactive until you explicitly enable it).

Step 2: Set Default UFW Policies

Before allowing specific ports, it is a security best practice to define your default policies. The safest approach is to block all incoming connections and allow all outgoing connections.

Block all incoming connections:sudo ufw default deny incoming

Allow all outgoing connections:sudo ufw default allow outgoing

Step 3: Allow SSH Connections (Crucial Step!)

If you are managing your server remotely via SSH, you must allow SSH connections before enabling UFW. If you skip this step, you will lock yourself out of your own server!

Run this command to allow SSH:sudo ufw allow ssh

Alternatively, you can specify the port number explicitly:sudo ufw allow 22/tcp

Step 4: Allow Other Common Services (HTTP & HTTPS)

If your server hosts a web application or blog (like Nginx or Apache), you need to open web ports so visitors can access your site.

Allow HTTP (Port 80):sudo ufw allow http

Allow HTTPS (Port 443):sudo ufw allow https

Allow custom port range (Example: Port 3000):sudo ufw allow 3000/tcp

Step 5: Enable the Firewall

Once you have configured your rules, it is time to turn on UFW.

Run the following command:sudo ufw enable

System Warning: You will see a prompt saying, "Command may disrupt existing ssh connections. Proceed with operation (y|n)?"

Type y and press Enter because you already allowed SSH in Step 3.

Step 6: Check UFW Status and Rules

To verify that your firewall is active and check which rules are currently applied, run:sudo ufw status verbose

You will see an active status output displaying all allowed ports and IP configurations.

Conclusion

You have successfully installed and configured UFW on Ubuntu 24.04! Your server is now heavily fortified against unauthorized incoming traffic. Regularly check your firewall logs and maintain secure access protocols to keep your infrastructure safe.

Comments

Popular posts from this blog

Linux Server Hardening Best Practices: Essential Steps to Secure Your Server

Top 10 Essential Linux Commands for DevOps Engineers

Quantum Computing in 2026: Why Traditional Encryption is Facing Its Biggest Threat