Start typing to search across invoices, services, domains, tickets, and more...
When a newly deployed website, database or application cannot be reached from outside, the firewall is often blocking the port. This guide covers the two most common tools for Linux firewall configuration: firewalld, the default on CentOS, Rocky Linux and AlmaLinux, and ufw, widely used on Ubuntu and Debian. You will learn how to check status, open ports, restrict by source IP and delete rules. Run all commands as root.
Use only one firewall manager per server; running firewalld and ufw together leads to conflicting rules. Check which one is active: RHEL-family systems usually run firewalld, Ubuntu uses ufw (often disabled by default), and some minimal Debian images have neither installed.
systemctl is-active firewalld # CentOS / Rocky / AlmaLinux
ufw status # Debian / Ubuntu
firewalld organises rules into zones, and the main network interface is normally in the public zone. After installing and starting it, --list-all shows the allowed services and ports — usually only ssh by default.
# Install and start firewalld (CentOS / Rocky / AlmaLinux)
dnf install -y firewalld
systemctl enable --now firewalld
firewall-cmd --state
firewall-cmd --get-active-zones
firewall-cmd --list-all
You can allow traffic by service name (http, https) or by port number or range. --permanent writes the rule to the permanent configuration, which only takes effect after --reload; rules added without --permanent apply immediately but are lost on reboot.
# Open by service name
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
# Open by port / range
firewall-cmd --permanent --add-port=8080/tcp
firewall-cmd --permanent --add-port=10000-10100/udp
# Apply and verify
firewall-cmd --reload
firewall-cmd --list-ports
firewall-cmd --list-services
Sensitive ports such as databases and admin panels should not be open to the whole internet. Use a rich rule to allow only a specific IP or subnet, and remove ports you no longer need with --remove-port.
# Allow MySQL 3306 only from one subnet
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.0/24" port port="3306" protocol="tcp" accept'
# Remove a port
firewall-cmd --permanent --remove-port=8080/tcp
firewall-cmd --reload
ufw is Ubuntu's uncomplicated firewall with an easy syntax. Allow SSH before anything else, then set the default policy to deny incoming and allow outgoing traffic. ufw enable warns that it may disrupt SSH connections; once SSH is allowed, answer y.
# Debian / Ubuntu
apt update && apt install -y ufw
# Allow SSH FIRST (use your custom port if you changed it)
ufw allow 22/tcp
ufw default deny incoming
ufw default allow outgoing
ufw enable
ufw status verbose
Use allow to open ports; port ranges require a protocol. The from keyword limits the source IP. To delete a rule, list rules with numbers and delete by number.
ufw allow 80/tcp
ufw allow 443/tcp
ufw allow 10000:10100/udp
ufw allow from 198.51.100.0/24 to any port 3306 proto tcp
# Delete a rule by number
ufw status numbered
ufw delete 3
Run ss -tlnp to confirm the application is listening on that port and on 0.0.0.0 rather than 127.0.0.1. Then check the application's own configuration and any platform-level security policy. Open a ticket if it still fails.
Technically yes (systemctl stop firewalld or ufw disable), but it is not recommended on a public server. Allow only the ports you need and deny everything else.
Log in via the VNC console and run firewall-cmd --permanent --add-service=ssh && firewall-cmd --reload or ufw allow 22/tcp to allow SSH again.
Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, operating system, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.