Updated: 28 September 2026 · Applies to: ufw, firewalld and nftables on Self-managed dedicated servers
A firewall on a server with many IP addresses can treat each address differently: web traffic on one address, a database only for your office on another, nothing at all on a third. This guide shows the rules with ufw (Ubuntu), firewalld (AlmaLinux and Rocky Linux) and nftables. It also names the most common ways that a firewall is bypassed.
Before you start
- Allow SSH first and keep a second SSH session open while you test. If you lock yourself out, use the IPMI console (How to get started with Console Redirection of an out-of-band-management?).
- Write down what should reach which address (for example:
203.0.113.11port 443 for everyone,203.0.113.12port 3306 only for your office IP).
ufw (Ubuntu)
sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw allow OpenSSH # web site on 203.0.113.11 for everyone sudo ufw allow proto tcp from any to 203.0.113.11 port 80,443 # database on 203.0.113.12 only for one office address sudo ufw allow proto tcp from 198.51.100.7 to 203.0.113.12 port 3306 sudo ufw enable sudo ufw status numbered
Delete a rule with sudo ufw delete NUMBER (from the numbered list). A rule that names a destination address applies only to traffic sent to that address.
firewalld (AlmaLinux and Rocky Linux)
sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" destination address="203.0.113.11" port port="443" protocol="tcp" accept' sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7" destination address="203.0.113.12" port port="3306" protocol="tcp" accept' sudo firewall-cmd --reload sudo firewall-cmd --list-rich-rules
nftables
A small rule set in /etc/nftables.conf:
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
ct state established,related accept
iif lo accept
tcp dport 22 accept
ip protocol icmp accept
ip daddr 203.0.113.11 tcp dport { 80, 443 } accept
ip saddr 198.51.100.7 ip daddr 203.0.113.12 tcp dport 3306 accept
}
}
Load it with sudo nft -f /etc/nftables.conf and enable it at boot with sudo systemctl enable nftables. Do not run nftables together with ufw or firewalld; choose one tool.
Check from outside
nc -vz 203.0.113.11 443 # should connect nc -vz 203.0.113.12 3306 # should fail from any other address
Ways a firewall gets bypassed
- Docker. Ports that you publish with
-p 8080:80are opened by Docker in the packet filter and can bypass ufw. Publish on a specific address (-p 203.0.113.11:8080:80) or on127.0.0.1and put a proxy in front. - Services on 0.0.0.0. A database that listens on all addresses is reachable on every IP you own. Bind it to one address or to 127.0.0.1.
- IPv6. If your server has IPv6, add rules for it too (ufw does this when
IPV6=yesis set in/etc/default/ufw).
Frequently asked questions
Do I need a firewall if my provider filters traffic?
Yes. Filtering in the network protects against attacks on the network. The firewall on the server decides which of your own services are exposed.
Where can I get help with rules?
Our engineers can review or write your rules by the task (First steps after your dedicated server is delivered: a checklist has the first steps).
Need a dedicated server, more IP addresses, or a hand with the setup?
- Unmanaged dedicated servers: full root access and IPv4 subnets from /29 up to /24, ordered with the server or added later.
- Managed dedicated servers: our team looks after the operating system, updates, security and monitoring.
- Dedicated server locations: choose the country and data centre when you order.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
