Before you begin
- Open the VNC console and keep it available.
- Confirm your SSH port; do not assume it is 22 if you changed it.
- Record existing firewall rules. Check IPv6 access as well as IPv4.
- If Docker or another tool manages firewall rules, review how those rules interact with UFW before relying on it.
Allow access before enabling the firewall
Install UFW if necessary, then inspect its state:Recover access
If SSH fails, use the already-open console to inspect rules. Correct the specific rule; if needed for recovery,sudo ufw disable temporarily disables UFW. Restore the intended protections after testing. Do not run ufw reset as a routine repair because it removes your configured rules.
When backing up UFW configuration, include /etc/ufw/, including both IPv4 and IPv6 rule files. Keep a note of whether the firewall was enabled.