How To Set Up a Firewall with UFW on Debian 13

How To Set Up a Firewall with UFW on Debian 13

A firewall is a security system that controls inbound and outbound access to a system. On a Linux server, a firewall is a crucial component to add as a security measure. In general, a firewall can be either hardware or software that prevents unauthorized access and protects the network from threats such as malware, DDoS attacks, and hacking. UFW is an iptables front-end feature in Debian 13 that can be used to configure a firewall system. UFW filters data and creates rules about what data can enter or exit a computer system. In this guide, we will show you how to set up a firewall using UFW (Uncomplicated Firewall) on Debian 13.

Prerequisites

  • A Debian 13 VPS
  • SSH root access or a regular system user with sudo privileges

Conventions

# – given commands should be executed with root privileges either directly as a root user or by use of sudo command
$ – given commands should be executed as a regular user

Step 1. Update the System

Let’s log in to your Debian 13 VPS through SSH as a root user or as a regular user with sudo privileges.

ssh root@IP_Address -p Port_number

If you cannot log in as root, remember to substitute “root” with a user that has sudo privileges. Additionally, change “IP_Address” and “Port_Number”; make sure they match your server’s respective IP address and SSH port.

You can check whether you have the correct Debian version installed on your server with the following command:

# lsb_release -a

You should get this output:

No LSB modules are available.
Distributor ID: Debian
Description:  Debian GNU/Linux 13 (trixie)
Release:  13
Codename: trixie

Step 2. Install UFW

First, let’s check whether UFW is installed.

# apt list | grep ufw

The command will print a message similar to this:

WARNING: apt does not have a stable CLI interface. Use with caution in scripts.

gufw/stable 24.04.0-3 all
libqt6protobufwellknowntypes6/stable 6.8.2-3 amd64
ufw/stable 0.36.2-9 all

If UFW is installed, it will look like this:

WARNING: apt does not have a stable CLI interface. Use with caution in scripts.

gufw/stable 24.04.0-3 all
libqt6protobufwellknowntypes6/stable 6.8.2-3 amd64
ufw/stable,now 0.36.2-9 all [installed]

Since it’s not installed on our Debian 13 system, we can proceed with installing it now.

# apt install ufw

Step 3. Set Default Policy

By default, UFW blocks (allows) all incoming packets and allows (allows) all outgoing packets. To set UFW’s default policies:

# ufw default deny incoming
# ufw default allow outgoing

Step 4. Allow SSH

If you connect to your server remotely (using SSH), you must allow the SSH port before enabling the firewall. Failure to do so will result in your SSH session being disconnected and your server access being blocked.

# ufw allow ssh

If your SSH service is listening on a port other than 22, let’s say 7022, you can execute the command below:

# ufw allow 7022/tcp

Step 5. Open Ports

Next, allow packets for specific protocol connections to enter the server; UFW will block all other connections.

# ufw allow 80
# ufw allow 443
# ufw allow 21

The commands above will open port 80 (HTTP), 443 (HTTPS), and 21 (FTP). If you want to open another port, simply run:

# ufw allow [PORT_NUMBER]

where [PORT_NUMBER] is a number.

We can also open a port range; for example, we can open ports between 12000 and 22000:

# ufw allow 12000:22000/tcp
# ufw allow 12000:22000/udp

Step 6. Whitelist IP Address

If you want to whitelist or allow an IP address, run the command below:

# ufw allow from 123.123.123.123

Replace 123.123.123.123 with the IP address you want to whitelist.

To whitelist or allow an IP address to access a specific service, for example, SSH, run this command:

# ufw allow from 123.123.123.123 to any port 22

To allow the whole network 123.123.123.0/24 to access SSH, we can execute the command below:

# ufw allow from 192.168.10.20 to any port 22

Step 7. Activate UFW

At this point, UFW is not activated yet. We can check it using this command:

# ufw status

The command will print this message on your screen:

Status: inactive

So, to activate it, simply execute this:

# ufw enable

You will be prompted about SSH; this is the complete message:

Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
Firewall is active and enabled on system startup

That’s it! UFW has been enabled. You can check the status again now.

# ufw status

You will see this:

Status: active

To                         Action      From
--                         ------      ----
22/tcp                     ALLOW       Anywhere                  
80                         ALLOW       Anywhere                  
443                        ALLOW       Anywhere                  
21                         ALLOW       Anywhere                  
12000:22000/tcp            ALLOW       Anywhere                  
12000:22000/udp            ALLOW       Anywhere                  
Anywhere                   ALLOW       123.123.123.123           
22                         ALLOW       123.123.123.123           
22                         ALLOW       192.168.10.20             
22/tcp (v6)                ALLOW       Anywhere (v6)             
80 (v6)                    ALLOW       Anywhere (v6)             
443 (v6)                   ALLOW       Anywhere (v6)             
21 (v6)                    ALLOW       Anywhere (v6)             
12000:22000/tcp (v6)       ALLOW       Anywhere (v6)             
12000:22000/udp (v6)       ALLOW       Anywhere (v6)

However, to check the status with more detailed information, we can run:

# ufw status verbose

The command will print this result:

Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), disabled (routed)
New profiles: skip

To                         Action      From
--                         ------      ----
22/tcp                     ALLOW IN    Anywhere                  
80                         ALLOW IN    Anywhere                  
443                        ALLOW IN    Anywhere                  
21                         ALLOW IN    Anywhere                  
12000:22000/tcp            ALLOW IN    Anywhere                  
12000:22000/udp            ALLOW IN    Anywhere                  
Anywhere                   ALLOW IN    123.123.123.123           
22                         ALLOW IN    123.123.123.123           
22                         ALLOW IN    192.168.10.20             
22/tcp (v6)                ALLOW IN    Anywhere (v6)             
80 (v6)                    ALLOW IN    Anywhere (v6)             
443 (v6)                   ALLOW IN    Anywhere (v6)             
21 (v6)                    ALLOW IN    Anywhere (v6)             
12000:22000/tcp (v6)       ALLOW IN    Anywhere (v6)             
12000:22000/udp (v6)       ALLOW IN    Anywhere (v6)   

Step 8. Delete Rules

Now, if you want to delete a firewall rule, for example, delete a rule that opens the HTTP port, you can execute this command:

# ufw delete allow 80

Or

# ufw delete allow http

Another way to delete a firewall rule is to display all numbered rules.

# ufw status numbered

The result is:

Need a fast and easy fix?
✔ Unlimited Managed Support
✔ Supports Your Software
✔ 2 CPU Cores
✔ 2 GB RAM
✔ 50 GB PCIe4 NVMe Disk
✔ 1854 GeekBench Score
✔ Unmetered Data Transfer
NVME 2 VPS

Now just $43 .99
/mo

GET YOUR VPS
Status: active

     To                         Action      From
     --                         ------      ----
[ 1] 22/tcp                     ALLOW IN    Anywhere                  
[ 2] 443                        ALLOW IN    Anywhere                  
[ 3] 21                         ALLOW IN    Anywhere                  
[ 4] 12000:22000/tcp            ALLOW IN    Anywhere                  
[ 5] 12000:22000/udp            ALLOW IN    Anywhere                  
[ 6] Anywhere                   ALLOW IN    123.123.123.123           
[ 7] 22                         ALLOW IN    123.123.123.123           
[ 8] 22                         ALLOW IN    192.168.10.20             
[ 9] 22/tcp (v6)                ALLOW IN    Anywhere (v6)             
[10] 443 (v6)                   ALLOW IN    Anywhere (v6)             
[11] 21 (v6)                    ALLOW IN    Anywhere (v6)             
[12] 12000:22000/tcp (v6)       ALLOW IN    Anywhere (v6)             
[13] 12000:22000/udp (v6)       ALLOW IN    Anywhere (v6)                    

As you can see above, the firewall rules are numbered on the left. You can check the number you want to delete and run this command:

# ufw delete 2

You will be asked for a YES/NO question, just to confirm if you want to delete the rule. This is the message printed on the screen after running the command:

Deleting:
 allow 443
Proceed with operation (y|n)? y
Rule deleted

If you plan on deactivating UFW, run this:

# ufw disable

You can also delete all rules with a single command if you want to start over.

# ufw reset

You’ve Installed Firewall with UFW on Debian 13

That’s it! You have learned how to configure a firewall using UFW (Uncomplicated Firewall) on Debian 13.

Of course, you don’t have to set up a firewall with UFW on Debian 13 if you have an active Debian hosting service with us, in which case you can simply ask our expert Linux administrators to install and configure UFW on Debian 13 for you for free. They are available 24×7 and will take care of your request immediately.

If you liked this post about how to set up a firewall with UFW on Debian 13, please share it with your friends or leave a comment below.

Leave a Comment