sudo ufw allow 22 sudo ufw status verbose Pick an action, port, and protocol, optionally restrict the source, then copy a ufw rule ready for your server.
sudo ufw allow 22 sudo ufw status verbose ufw limit ssh allows connections but blocks an IP that attempts 6 or more connections within 30 seconds, which blunts brute-force attempts without any extra tooling. It is the better default for port 22 unless you already run fail2ban. Remember to allow SSH before running ufw enable on a remote server, or you will lock yourself out.
This ufw rule generator covers the rules that come up on nearly every Linux server: opening SSH safely with rate limiting, exposing web ports, restricting a database to your LAN, and blocking unwanted sources. Pair rules with comments so future-you knows why each port is open.
deny drops packets silently so the sender gets no response and eventually times out. reject actively sends back a refusal. reject is friendlier for internal networks where you want fast failures; deny reveals less to scanners on public interfaces.
Docker writes its own iptables rules ahead of ufw when publishing ports, so -p 8080:80 is reachable even if ufw never allowed it. Bind containers to 127.0.0.1 or configure DOCKER-USER chain rules when this matters.
Add your SSH rule first (ufw limit 22/tcp), verify it with ufw show added, and only then run ufw enable. The enable step warns about disrupting existing connections; with the SSH rule in place it is safe to proceed.
Run ufw status numbered to list rules with indexes, then ufw delete N. You can also repeat the original rule prefixed with delete, e.g. ufw delete allow 8080/tcp.