VPS Firewall Setup with UFW and iptables: Port Hardening & Lockout Prevention
A hands-on sysadmin guide to securing a Linux cloud VPS with UFW and iptables, implementing strict ingress filtering while preventing accidental connection loss.
Securing an unmanaged Linux virtual private server immediately after initial provisioning is an essential sysadmin responsibility. When a cloud VPS is assigned a public IPv4 address, automated scanning bots and credential brute-force scripts begin probing exposed ports within minutes. Configuring a robust host-based firewall using the Uncomplicated Firewall (UFW) or underlying netfilter iptables rules ensures that only legitimate application ports are accessible, while completely blocking unauthorized ingress traffic.
Understanding UFW and the Linux Netfilter Subsystem
In modern Linux distributions such as Ubuntu and Debian, packet filtering is handled inside the Linux kernel by the Netfilter framework. Historically, administrators wrote complex rules directly using the iptables command-line utility. While iptables provides granular control over network packet chains (INPUT, OUTPUT, FORWARD, PREROUTING, and POSTROUTING), crafting syntax-heavy rule sets is prone to syntax errors that can accidentally drop administrative connections.
The Uncomplicated Firewall (UFW) serves as a user-friendly management frontend for iptables and netfilter. It abstracts complex chain rules into intuitive commands while maintaining strict security boundaries. On an unmanaged KVM VPS where you maintain full root privileges, mastering UFW allows you to deploy defense-in-depth network policies in minutes.
Step 1: The Critical Lockout Prevention Protocol
The most common mistake when configuring a Linux firewall is enabling a default-deny policy before explicitly allowing administrative SSH access. Once enabled, the firewall immediately terminates active remote sessions, locking the administrator out of the machine.
Always follow this mandatory defensive protocol:
# 1. Verify UFW is currently inactive before making changes
sudo ufw status
# 2. Establish default traffic policies (deny all ingress, allow all egress)
sudo ufw default deny incoming
sudo ufw default allow outgoing
# 3. Explicitly allow SSH BEFORE activating the firewall
# If using standard port 22:
sudo ufw allow 22/tcp
# If using a custom SSH port (e.g., 2222):
sudo ufw allow 2222/tcp
# Or allow by application profile
sudo ufw allow OpenSSHCrucial Best Practice: Keep your existing SSH terminal window open. Do not close it. Open a second, independent terminal window on your local computer and attempt to connect via SSH to verify that the firewall permits incoming connections before exiting your primary session.
Step 2: Implementing SSH Brute-Force Rate Limiting
Even with SSH allowed, public-facing servers are subjected to persistent dictionary attacks. UFW includes a built-in rate-limiting capability that denies connections from an IP address that attempts six or more connections within a 30-second window:
# Enable rate-limiting on SSH
sudo ufw limit 22/tcpThis simple command effectively mitigates automated credential-stuffing tools while permitting legitimate administrative access.
Step 3: Opening Production Web and Application Ports
Next, open only the specific ports required by your application stack:
# Allow standard HTTP and HTTPS traffic
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# If running an application API on a specific port (e.g., 8000 or 3000)
# restricted to a specific office IP address:
sudo ufw allow from 203.0.113.50 to any port 8000 proto tcp
# Allow internal private communication across Docker or VPN interfaces
sudo ufw allow in on wg0 to anyStep 4: Activating and Verifying Firewall State
Once all necessary rules are registered, activate UFW and verify the active ruleset:
# Enable the firewall
sudo ufw enable
# Check detailed status with rule numbers
sudo ufw status verbose
sudo ufw status numberedIf you need to delete a rule in the future, reference its number directly:
# Delete rule number 3
sudo ufw delete 3Step 5: Inspecting Raw iptables Chains for Advanced Auditing
Because UFW manages rules on top of iptables, advanced administrators can inspect the underlying kernel packet counters to observe real-time packet filtering activity:
# List all iptables rules with packet and byte counters
sudo iptables -L -n -v
# Inspect the specific UFW input user chains
sudo iptables -S ufw-user-inputExamining packet counters allows you to verify that dropped packets are incrementing as expected when unauthorized port scans strike the server.
Deploying Secure Workloads on VPSWala Cloud VPS
A well-hardened firewall ensures that your compute resources remain dedicated to genuine customer traffic. VPSWala provides unmanaged KVM cloud VPS plans starting from Rs 149 per month with full root access, RAID NVMe storage, and scalable configurations up to 128 GB RAM. For demanding production databases and heavy workloads, our AMD Ryzen 9 9950X VPS instances deliver exceptional performance with DDR5 memory and up to 5.7 GHz boost clock speeds.
Configure your cloud server on VPSWala KVM Cloud VPS, or discover high-frequency instances on VPSWala 9950X VPS.
Sources
Not sure which size?
Send the stack, get a size.
Tell us the operating system, application stack, current traffic, database size and where it hurts today. You get a sizing recommendation, the matching plan and a price.
Related
Deploying Next.js SSR on a Linux VPS: Standalone Build, PM2 & Nginx Proxy
Learn how to deploy a server-rendered Next.js application on a Linux KVM VPS using standalone build artifacts, PM2 cluster management, and Nginx.
VPS Hosting for Bhopal: Which VPSWala Node to Pick and How to Test It
A practical routing and workload sizing guide for developers and businesses in Bhopal to evaluate VPSWala cloud nodes and verify network path stability.
VPS Backup Automation with BorgBackup: Deduplication, Pruning & systemd Timers
A complete guide to automating secure, deduplicated Linux VPS backups using BorgBackup, SSH key authentication, retention pruning, and systemd timers.