Skip to main content
05 / How-to · Access and security · 5.6

Firewall

Open, block or limit to one address a TCP port of the server from the Firewall page.

Type
How-to guide
Needs
An administrator account · The server's firewall (ufw) installed; active for the rules to take effect
Version
unreleased
Last verified
Unverified

The Firewall page, in the Server group, shows whether the firewall is active and its rules, as the system reports them. Administrators add and remove rules; read-only accounts only see them.

Neither the installer nor the panel ever turns the firewall on: many servers already sit behind their provider's firewall, and a script that turns ufw on can lock you out, for example when SSH listens on another port. On a freshly created cloud server ufw is usually installed but off, and the page says inactive. While it is inactive, rules are saved but have no effect: the page shows them with The firewall is inactive: these rules are stored, and apply only once it is enabled.

What the installer does​

  • ufw active: it opens the ports SSH listens on (those sshd -T reports; 22 when it reports none), 80/tcp, 443/tcp, 443/udp (HTTP/3) and 8443/tcp.
  • ufw installed but off: it changes nothing, and at the end of the installation prints the commands that turn it on with SSH, the sites and the panel open.
  • ufw not installed: nothing.

Turn the firewall on​

On the server, as root, run the commands the installer printed. They have this shape, with one ufw allow <port>/tcp for each port SSH listens on:

bash
sshd -T | grep '^port '
ufw allow 22/tcp && ufw allow 80/tcp && ufw allow 443/tcp && ufw allow 8443/tcp && ufw allow 443/udp && ufw enable

The first line shows SSH's ports: if it is not just 22, put yours in its place.

Once the firewall is active, the page says active and the saved rules apply.

Open a port​

  1. Open Firewall.
  2. In Add or remove a rule, choose the Action Allow port.
  3. Type the Port, 1 to 65535.
  4. To open it to one address only, type the IP or the network (for example 203.0.113.7 or 203.0.113.0/24) into Only from this IP.
  5. Press Apply.

From the panel, rules are always TCP.

Block a port​

As above, with the Action Deny port. With Only from this IP you block the port for that address only.

Remove a rule​

Choose the Action Delete rule, with the same Port and the same Only from this IP as the rule to remove, and press Apply. The panel removes the allow and the deny rule of exactly that shape, and leaves the port's other rules alone.

The ports that stay open​

The panel refuses any rule that would lock you or the sites out:

  • the ports SSH listens on (usually 22);
  • 80 and 443, the sites';
  • 8443, the panel's.

For these ports you cannot remove the rule or block them for everyone. You can block them for a single address, or add allow rules.

From the API​

GET /api/firewall reads the status. POST /api/firewall/rule with {"action": "allow", "port": 3306, "proto": "tcp", "from": "203.0.113.7"} applies a rule; action is allow, deny or delete, proto is tcp or udp. Every rule lands in the Audit log.

Next step​

Keep a way back in should you lose the password: recover administrator access.

Was this page useful?
Edit this page ↗