---
title: "Linux Firewall Setup with UFW: A Guide | Ameya Shenoy"
description: "Set up a Linux server firewall with UFW. Follow Ameya Shenoy’s practical notes on installation, default policies, app rules and managing firewall access."
canonical: "https://www.codingcoffee.dev/blog/firewall-init"
published: "2018-09-05"
tags: "blog"
---

# Firewall init

By Ameya Shenoy · Published 2018-09-05

Set up a Linux server firewall with UFW. Follow Ameya Shenoy’s practical notes on installation, default policies, app rules and managing firewall access.

Firewall is used to keep a check on the incoming and outgoing connections.

We shall be using `ufw` (**Uncomplicated Firewall**) to close unwanted incoming connections from the Internet and allow outgoing ones.

It's preferable to not use Scaleway servers, as something or the other used to get messed up on those. Digital Ocean and Vultr seem to do just fine.

Make sure this is the first thing you do when setting up a server. This is to ensure there is no data loss or time loss if anything goes wrong. There is a major chance of losing complete access to the server in case you don't configure something properly. So make sure to backup your data locally or on another server to prevent any data loss.

## Installation

```bash
apt install ufw
```

## Configuration

Edit `/etc/default/ufw` and modify the policies:

```
DEFAULT_INPUT_POLICY="ACCEPT"
DEFAULT_OUTPUT_POLICY="ACCEPT"
DEFAULT_FORWARD_POLICY="ACCEPT"
```

Append a drop-all rule to the INPUT chain. Edit `/etc/ufw/after.rules`, add this line just before the final `COMMIT` line:

```
-A ufw-reject-input -j DROP
```

Disable `ufw` logging (this seems to cause issues with Scaleway's default kernel):

```bash
ufw logging off
```

Fix permissions (seems to be necessary on some setups):

```bash
chmod 751 /etc/default
chmod 751 /etc
chmod 751 /usr
```

## Basic Setup

Setup a basic configuration to allow SSH, HTTPS and HTTP incoming:

```bash
ufw default deny incoming
ufw default allow outgoing
ufw allow ssh
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
```

In a new terminal window check that you can still access your host via ssh.

## Management

Check the configuration at any time:

```bash
ufw status verbose
```

Disable the `ufw` configuration at any time:

```bash
sudo ufw disable
```

---

Canonical page: https://www.codingcoffee.dev/blog/firewall-init

[Site guide](/llms.txt) · [Contact](/contact) · [Sitemap](/sitemap-index.xml)
