The Firewall page, in the Server group, shows whether the firewall is active and its rules, as the system reports them. Administrators add and remove rules; read-only accounts only see them.
Neither the installer nor the panel ever turns the firewall on: many servers already sit behind their provider's firewall, and a script that turns ufw on can lock you out, for example when SSH listens on another port. On a freshly created cloud server ufw is usually installed but off, and the page says inactive. While it is inactive, rules are saved but have no effect: the page shows them with The firewall is inactive: these rules are stored, and apply only once it is enabled.
What the installer does
- ufw active: it opens the ports SSH listens on (those
sshd -Treports; 22 when it reports none), 80/tcp, 443/tcp, 443/udp (HTTP/3) and 8443/tcp. - ufw installed but off: it changes nothing, and at the end of the installation prints the commands that turn it on with SSH, the sites and the panel open.
- ufw not installed: nothing.
Turn the firewall on
On the server, as root, run the commands the installer printed. They have this shape, with one
ufw allow <port>/tcp for each port SSH listens on:
sshd -T | grep '^port '
ufw allow 22/tcp && ufw allow 80/tcp && ufw allow 443/tcp && ufw allow 8443/tcp && ufw allow 443/udp && ufw enable
The first line shows SSH's ports: if it is not just 22, put yours in its place.
Once the firewall is active, the page says active and the saved rules apply.
Open a port
- Open Firewall.
- In Add or remove a rule, choose the Action Allow port.
- Type the Port, 1 to 65535.
- To open it to one address only, type the IP or the network (for example
203.0.113.7or203.0.113.0/24) into Only from this IP. - Press Apply.
From the panel, rules are always TCP.
Block a port
As above, with the Action Deny port. With Only from this IP you block the port for that address only.
Remove a rule
Choose the Action Delete rule, with the same Port and the same Only from this IP as the rule to remove, and press Apply. The panel removes the allow and the deny rule of exactly that shape, and leaves the port's other rules alone.
The ports that stay open
The panel refuses any rule that would lock you or the sites out:
- the ports SSH listens on (usually 22);
- 80 and 443, the sites';
- 8443, the panel's.
For these ports you cannot remove the rule or block them for everyone. You can block them for a single address, or add allow rules.
From the API
GET /api/firewall reads the status. POST /api/firewall/rule with
{"action": "allow", "port": 3306, "proto": "tcp", "from": "203.0.113.7"} applies a rule; action
is allow, deny or delete, proto is tcp or udp. Every rule lands in the Audit log.
Next step
Keep a way back in should you lose the password: recover administrator access.