What is a software firewall?
A firewall is a guard that decides which connections may reach your server. A software firewall is a program running on the server itself, not a separate device. Without one, every service on your server may be reachable by the whole internet.
Root is the all-powerful user on Linux. Commands here use root. SSH is a safe way to type commands on a server from your computer.
Option 1: UFW (Ubuntu and Debian)
UFW stands for Uncomplicated Firewall. It is easy to learn.
- Connect to your server with SSH as root.
- Install UFW if needed:
apt update && apt install ufw -y
This refreshes the package list and installs UFW.
- Set the default rules:
ufw default deny incoming
ufw default allow outgoing
This blocks all incoming traffic unless you allow it, and lets your server connect out.
- Allow what you need:
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
These allow SSH, normal web traffic and secure web traffic. If you changed your SSH port, use that number instead of 22.
- Turn the firewall on:
ufw enable
This starts the firewall now and at every boot.
- Check it:
ufw status verbose
Option 2: firewalld (AlmaLinux, Rocky Linux, CentOS)
- Install and start it:
dnf install firewalld -y
systemctl enable --now firewalld
This installs firewalld and starts it now and at boot.
- Allow services:
firewall-cmd --permanent --add-service=ssh
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
The last line applies your changes.
Option 3: CSF on cPanel servers
ConfigServer Security and Firewall (CSF) is popular on servers with WHM and cPanel. It has a ready web page inside WHM. Ask Hostvento support whether it is already installed on your server. Do not run two firewalls at the same time, because they can clash.
Only open what you need
- Open only ports you really use. A port is a numbered door on the server.
- Allow your own IP for SSH if you can.
- Review the rules now and then.
Need help? Open a support ticket.
Quick recap
- A software firewall runs on the server and filters traffic.
- Use UFW on Ubuntu or Debian, firewalld on the Red Hat family.
- Allow SSH before you turn it on.
- Use only one firewall tool at a time.