sudo ufw limit 22/tcp comment 'ssh'

ufw Rule Builder

Pick an action, port, and protocol, optionally restrict the source, then copy a ufw rule ready for your server.

e.g. 22, 8000:8100 (ranges need a protocol)
IP or subnet, e.g. 192.168.1.0/24. Empty means any.
Shows in ufw status verbose. Quoted automatically.
sudo ufw allow 22
sudo ufw status verbose

limit vs allow for SSH

ufw limit ssh allows connections but blocks an IP that attempts 6 or more connections within 30 seconds, which blunts brute-force attempts without any extra tooling. It is the better default for port 22 unless you already run fail2ban. Remember to allow SSH before running ufw enable on a remote server, or you will lock yourself out.

Uncomplicated Firewall rule helper

This ufw rule generator covers the rules that come up on nearly every Linux server: opening SSH safely with rate limiting, exposing web ports, restricting a database to your LAN, and blocking unwanted sources. Pair rules with comments so future-you knows why each port is open.

ufw FAQ

What is the difference between deny and reject?

deny drops packets silently so the sender gets no response and eventually times out. reject actively sends back a refusal. reject is friendlier for internal networks where you want fast failures; deny reveals less to scanners on public interfaces.

Why does my Docker container port ignore ufw rules?

Docker writes its own iptables rules ahead of ufw when publishing ports, so -p 8080:80 is reachable even if ufw never allowed it. Bind containers to 127.0.0.1 or configure DOCKER-USER chain rules when this matters.

How do I safely enable ufw over SSH?

Add your SSH rule first (ufw limit 22/tcp), verify it with ufw show added, and only then run ufw enable. The enable step warns about disrupting existing connections; with the SSH rule in place it is safe to proceed.

How do I delete a rule I added?

Run ufw status numbered to list rules with indexes, then ufw delete N. You can also repeat the original rule prefixed with delete, e.g. ufw delete allow 8080/tcp.