whatis firewall
Firewall
Also known as: packet filter, netfilter
Rules that allow or block network traffic by address, port, and protocol. Linux firewalls are built on the kernel's netfilter framework.
What Is a Firewall in Linux?
The kernel does the actual filtering through netfilter. nftables and the older iptables are the low-level tools for writing rules, while ufw and firewalld are friendlier front ends that generate those rules for you.
A sensible server default is to drop incoming traffic except for the ports you explicitly serve, and allow outgoing and established connections.
Example
sudo ufw default deny incoming
sudo ufw allow 22/tcp
sudo ufw enable Learn more about Firewall
- Linux Firewall Basics Linux firewalls control which network traffic is allowed in and out of your system. This guide covers the concepts, ufw for simple setups, and an introduction to the underlying nftables rules that power them all.
- firewalld Explained: Zones, Services, and Runtime vs Permanent Fedora and RHEL ship firewalld rather than ufw, and its zone model confuses people arriving from other distributions. Here is how zones work and why half your rules disappear on reboot.
- nftables vs iptables nftables replaced iptables as the standard Linux packet filtering framework. This guide explains the differences, how to use both, and how to migrate from iptables rules to nftables.
Related tools
- ufw Rule Builder Build ufw firewall rules with allow/deny/limit actions, source restrictions, and comments.
- nftables Rule Builder Generate nftables rules and a stateful starter ruleset for the inet filter table.