ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Linux Server

Linux Firewall Setup: How to Open Ports with firewalld and ufw

6 steps 11 min read 5 views 0
On this page

When a newly deployed website, database or application cannot be reached from outside, the firewall is often blocking the port. This guide covers the two most common tools for Linux firewall configuration: firewalld, the default on CentOS, Rocky Linux and AlmaLinux, and ufw, widely used on Ubuntu and Debian. You will learn how to check status, open ports, restrict by source IP and delete rules. Run all commands as root.

Before enabling or changing a firewall, always allow your SSH port first (22, or your custom port), or you will lose remote access immediately. If that happens, recover via the VNC console in the client area.

Step 1: Find Out Which Firewall Your System Uses

Use only one firewall manager per server; running firewalld and ufw together leads to conflicting rules. Check which one is active: RHEL-family systems usually run firewalld, Ubuntu uses ufw (often disabled by default), and some minimal Debian images have neither installed.

systemctl is-active firewalld    # CentOS / Rocky / AlmaLinux
ufw status                       # Debian / Ubuntu

Step 2: Install firewalld and Check Its Status (CentOS / Rocky / AlmaLinux)

firewalld organises rules into zones, and the main network interface is normally in the public zone. After installing and starting it, --list-all shows the allowed services and ports — usually only ssh by default.

# Install and start firewalld (CentOS / Rocky / AlmaLinux)
dnf install -y firewalld
systemctl enable --now firewalld

firewall-cmd --state
firewall-cmd --get-active-zones
firewall-cmd --list-all

Step 3: Open Ports and Services in firewalld

You can allow traffic by service name (http, https) or by port number or range. --permanent writes the rule to the permanent configuration, which only takes effect after --reload; rules added without --permanent apply immediately but are lost on reboot.

# Open by service name
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https

# Open by port / range
firewall-cmd --permanent --add-port=8080/tcp
firewall-cmd --permanent --add-port=10000-10100/udp

# Apply and verify
firewall-cmd --reload
firewall-cmd --list-ports
firewall-cmd --list-services

Step 4: Restrict Source IPs and Remove Rules in firewalld

Sensitive ports such as databases and admin panels should not be open to the whole internet. Use a rich rule to allow only a specific IP or subnet, and remove ports you no longer need with --remove-port.

# Allow MySQL 3306 only from one subnet
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.0/24" port port="3306" protocol="tcp" accept'

# Remove a port
firewall-cmd --permanent --remove-port=8080/tcp
firewall-cmd --reload

Step 5: Install and Enable ufw (Ubuntu / Debian)

ufw is Ubuntu's uncomplicated firewall with an easy syntax. Allow SSH before anything else, then set the default policy to deny incoming and allow outgoing traffic. ufw enable warns that it may disrupt SSH connections; once SSH is allowed, answer y.

# Debian / Ubuntu
apt update && apt install -y ufw

# Allow SSH FIRST (use your custom port if you changed it)
ufw allow 22/tcp
ufw default deny incoming
ufw default allow outgoing
ufw enable
ufw status verbose

Step 6: Open Ports, Restrict IPs and Delete Rules in ufw

Use allow to open ports; port ranges require a protocol. The from keyword limits the source IP. To delete a rule, list rules with numbers and delete by number.

ufw allow 80/tcp
ufw allow 443/tcp
ufw allow 10000:10100/udp
ufw allow from 198.51.100.0/24 to any port 3306 proto tcp

# Delete a rule by number
ufw status numbered
ufw delete 3
Ports published by Docker containers are written straight into iptables and can bypass ufw rules. To restrict a container port, bind it to 127.0.0.1 in docker run or follow Docker's official firewall documentation.

FAQ

The port is open in the firewall but still unreachable.

Run ss -tlnp to confirm the application is listening on that port and on 0.0.0.0 rather than 127.0.0.1. Then check the application's own configuration and any platform-level security policy. Open a ticket if it still fails.

Can I just turn the firewall off?

Technically yes (systemctl stop firewalld or ufw disable), but it is not recommended on a public server. Allow only the ports you need and deny everything else.

SSH disconnected after I enabled the firewall.

Log in via the VNC console and run firewall-cmd --permanent --add-service=ssh && firewall-cmd --reload or ufw allow 22/tcp to allow SSH again.

Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, operating system, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.

Was this answer helpful?

Related Tutorials