Updated: 28 September 2026 · Applies to: ufw, firewalld and nftables on Self-managed dedicated servers

A firewall on a server with many IP addresses can treat each address differently: web traffic on one address, a database only for your office on another, nothing at all on a third. This guide shows the rules with ufw (Ubuntu), firewalld (AlmaLinux and Rocky Linux) and nftables. It also names the most common ways that a firewall is bypassed.

Before you start

ufw (Ubuntu)

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH

# web site on 203.0.113.11 for everyone
sudo ufw allow proto tcp from any to 203.0.113.11 port 80,443

# database on 203.0.113.12 only for one office address
sudo ufw allow proto tcp from 198.51.100.7 to 203.0.113.12 port 3306

sudo ufw enable
sudo ufw status numbered

Delete a rule with sudo ufw delete NUMBER (from the numbered list). A rule that names a destination address applies only to traffic sent to that address.

firewalld (AlmaLinux and Rocky Linux)

sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" destination address="203.0.113.11" port port="443" protocol="tcp" accept'
sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7" destination address="203.0.113.12" port port="3306" protocol="tcp" accept'
sudo firewall-cmd --reload
sudo firewall-cmd --list-rich-rules

nftables

A small rule set in /etc/nftables.conf:

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;
    ct state established,related accept
    iif lo accept
    tcp dport 22 accept
    ip protocol icmp accept
    ip daddr 203.0.113.11 tcp dport { 80, 443 } accept
    ip saddr 198.51.100.7 ip daddr 203.0.113.12 tcp dport 3306 accept
  }
}

Load it with sudo nft -f /etc/nftables.conf and enable it at boot with sudo systemctl enable nftables. Do not run nftables together with ufw or firewalld; choose one tool.

Check from outside

nc -vz 203.0.113.11 443     # should connect
nc -vz 203.0.113.12 3306    # should fail from any other address

Ways a firewall gets bypassed

  • Docker. Ports that you publish with -p 8080:80 are opened by Docker in the packet filter and can bypass ufw. Publish on a specific address (-p 203.0.113.11:8080:80) or on 127.0.0.1 and put a proxy in front.
  • Services on 0.0.0.0. A database that listens on all addresses is reachable on every IP you own. Bind it to one address or to 127.0.0.1.
  • IPv6. If your server has IPv6, add rules for it too (ufw does this when IPV6=yes is set in /etc/default/ufw).

Frequently asked questions

Do I need a firewall if my provider filters traffic?
Yes. Filtering in the network protects against attacks on the network. The firewall on the server decides which of your own services are exposed.

Where can I get help with rules?
Our engineers can review or write your rules by the task (First steps after your dedicated server is delivered: a checklist has the first steps).

Need a dedicated server, more IP addresses, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)