KVM VPS from Rs 149/mo. Mumbai, Noida and Jaipur nodes.

24×7 infrastructure operations Sales +91 98297 14343
vpswala.in
VPSWala 3 min read

VPS Firewall Setup with UFW and iptables: Port Hardening & Lockout Prevention

A hands-on sysadmin guide to securing a Linux cloud VPS with UFW and iptables, implementing strict ingress filtering while preventing accidental connection loss.

Securing an unmanaged Linux virtual private server immediately after initial provisioning is an essential sysadmin responsibility. When a cloud VPS is assigned a public IPv4 address, automated scanning bots and credential brute-force scripts begin probing exposed ports within minutes. Configuring a robust host-based firewall using the Uncomplicated Firewall (UFW) or underlying netfilter iptables rules ensures that only legitimate application ports are accessible, while completely blocking unauthorized ingress traffic.

Understanding UFW and the Linux Netfilter Subsystem

In modern Linux distributions such as Ubuntu and Debian, packet filtering is handled inside the Linux kernel by the Netfilter framework. Historically, administrators wrote complex rules directly using the iptables command-line utility. While iptables provides granular control over network packet chains (INPUT, OUTPUT, FORWARD, PREROUTING, and POSTROUTING), crafting syntax-heavy rule sets is prone to syntax errors that can accidentally drop administrative connections.

The Uncomplicated Firewall (UFW) serves as a user-friendly management frontend for iptables and netfilter. It abstracts complex chain rules into intuitive commands while maintaining strict security boundaries. On an unmanaged KVM VPS where you maintain full root privileges, mastering UFW allows you to deploy defense-in-depth network policies in minutes.

Step 1: The Critical Lockout Prevention Protocol

The most common mistake when configuring a Linux firewall is enabling a default-deny policy before explicitly allowing administrative SSH access. Once enabled, the firewall immediately terminates active remote sessions, locking the administrator out of the machine.

Always follow this mandatory defensive protocol:

# 1. Verify UFW is currently inactive before making changes
sudo ufw status

# 2. Establish default traffic policies (deny all ingress, allow all egress)
sudo ufw default deny incoming
sudo ufw default allow outgoing

# 3. Explicitly allow SSH BEFORE activating the firewall
# If using standard port 22:
sudo ufw allow 22/tcp

# If using a custom SSH port (e.g., 2222):
sudo ufw allow 2222/tcp

# Or allow by application profile
sudo ufw allow OpenSSH

Crucial Best Practice: Keep your existing SSH terminal window open. Do not close it. Open a second, independent terminal window on your local computer and attempt to connect via SSH to verify that the firewall permits incoming connections before exiting your primary session.

Step 2: Implementing SSH Brute-Force Rate Limiting

Even with SSH allowed, public-facing servers are subjected to persistent dictionary attacks. UFW includes a built-in rate-limiting capability that denies connections from an IP address that attempts six or more connections within a 30-second window:

# Enable rate-limiting on SSH
sudo ufw limit 22/tcp

This simple command effectively mitigates automated credential-stuffing tools while permitting legitimate administrative access.

Step 3: Opening Production Web and Application Ports

Next, open only the specific ports required by your application stack:

# Allow standard HTTP and HTTPS traffic
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

# If running an application API on a specific port (e.g., 8000 or 3000)
# restricted to a specific office IP address:
sudo ufw allow from 203.0.113.50 to any port 8000 proto tcp

# Allow internal private communication across Docker or VPN interfaces
sudo ufw allow in on wg0 to any

Step 4: Activating and Verifying Firewall State

Once all necessary rules are registered, activate UFW and verify the active ruleset:

# Enable the firewall
sudo ufw enable

# Check detailed status with rule numbers
sudo ufw status verbose
sudo ufw status numbered

If you need to delete a rule in the future, reference its number directly:

# Delete rule number 3
sudo ufw delete 3

Step 5: Inspecting Raw iptables Chains for Advanced Auditing

Because UFW manages rules on top of iptables, advanced administrators can inspect the underlying kernel packet counters to observe real-time packet filtering activity:

# List all iptables rules with packet and byte counters
sudo iptables -L -n -v

# Inspect the specific UFW input user chains
sudo iptables -S ufw-user-input

Examining packet counters allows you to verify that dropped packets are incrementing as expected when unauthorized port scans strike the server.

Deploying Secure Workloads on VPSWala Cloud VPS

A well-hardened firewall ensures that your compute resources remain dedicated to genuine customer traffic. VPSWala provides unmanaged KVM cloud VPS plans starting from Rs 149 per month with full root access, RAID NVMe storage, and scalable configurations up to 128 GB RAM. For demanding production databases and heavy workloads, our AMD Ryzen 9 9950X VPS instances deliver exceptional performance with DDR5 memory and up to 5.7 GHz boost clock speeds.

Configure your cloud server on VPSWala KVM Cloud VPS, or discover high-frequency instances on VPSWala 9950X VPS.


Sources

Not sure which size?

Send the stack, get a size.

Tell us the operating system, application stack, current traffic, database size and where it hurts today. You get a sizing recommendation, the matching plan and a price.

Related

More on this.

Get sizing help See VPS plans