whatis firewall

Firewall

Also known as: packet filter, netfilter

Rules that allow or block network traffic by address, port, and protocol. Linux firewalls are built on the kernel's netfilter framework.

What Is a Firewall in Linux?

The kernel does the actual filtering through netfilter. nftables and the older iptables are the low-level tools for writing rules, while ufw and firewalld are friendlier front ends that generate those rules for you.

A sensible server default is to drop incoming traffic except for the ports you explicitly serve, and allow outgoing and established connections.

Example

sudo ufw default deny incoming
sudo ufw allow 22/tcp
sudo ufw enable