Skip to main content
UFW is a firewall interface commonly used on Debian and Ubuntu. Enabling it before allowing your current SSH port can lock you out.

Before you begin

  • Open the VNC console and keep it available.
  • Confirm your SSH port; do not assume it is 22 if you changed it.
  • Record existing firewall rules. Check IPv6 access as well as IPv4.
  • If Docker or another tool manages firewall rules, review how those rules interact with UFW before relying on it.

Allow access before enabling the firewall

Install UFW if necessary, then inspect its state:
For SSH on port 22, allow it before enabling UFW. Replace 22 with your actual SSH port if different:
Open a second SSH session and verify login before closing the first. Allow other ports only for services you intend to expose, and restrict source addresses where practical.

Recover access

If SSH fails, use the already-open console to inspect rules. Correct the specific rule; if needed for recovery, sudo ufw disable temporarily disables UFW. Restore the intended protections after testing. Do not run ufw reset as a routine repair because it removes your configured rules. When backing up UFW configuration, include /etc/ufw/, including both IPv4 and IPv6 rule files. Keep a note of whether the firewall was enabled.