UFW Firewall Rules for Ubuntu Web Servers
A minimal UFW ruleset for public web servers: SSH, HTTP, HTTPS, and when to restrict admin ports.
Default deny posture
Public VPS instances receive constant scanning traffic. UFW simplifies iptables with readable commands: ufw default deny incoming, ufw default allow outgoing, then explicitly allow required services.
Always allow OpenSSH before enabling UFW remotely. Locking yourself out requires console access through your provider.
Vcom Web Tech applies the same baseline to Nginx, Docker, and mail relay hosts, then adds role-specific rules.
Web and admin access
Allow 80 and 443 for public sites. Restrict SSH to your office IP or VPN egress with ufw allow from x.x.x.x to any port 22 proto tcp when feasible.
Database ports should never be public. Bind PostgreSQL to localhost or a private network interface only.
If you expose monitoring dashboards, protect them with VPN or IP allowlists instead of obscure URLs.
Docker and UFW interactions
Docker can bypass UFW rules by manipulating iptables directly. Understand whether published container ports are exposed unexpectedly after docker compose up.
Use internal networks and publish only the reverse proxy when possible. Document any DOCKER-USER chain rules required to restore expected firewall behavior.
After major Docker upgrades, re-verify effective rules with ss and external port scans from a trusted scanner.
Maintenance
Store ufw status numbered output in git as documentation. Review quarterly when adding new services like SMTP submission or GitLab.
Automate fail2ban jails alongside UFW to reduce brute-force noise against SSH and web forms.
Change management for firewall rules should be as formal as application deploys.
Additional operational notes
Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.
When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.
Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.
Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.
Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.
Additional operational notes
Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.
When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.
Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.
Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.
Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.