
A firewall is a security system that controls inbound and outbound access to a system. On a Linux server, a firewall is a crucial component to add as a security measure. In general, a firewall can be either hardware or software that prevents unauthorized access and protects the network from threats such as malware, DDoS attacks, and hacking. UFW is an iptables front-end feature in Debian 13 that can be used to configure a firewall system. UFW filters data and creates rules about what data can enter or exit a computer system. In this guide, we will show you how to set up a firewall using UFW (Uncomplicated Firewall) on Debian 13.
Table of Contents
Prerequisites
- A Debian 13 VPS
- SSH root access or a regular system user with sudo privileges
Conventions
# – given commands should be executed with root privileges either directly as a root user or by use of sudo command
$ – given commands should be executed as a regular user
Step 1. Update the System
Let’s log in to your Debian 13 VPS through SSH as a root user or as a regular user with sudo privileges.
ssh root@IP_Address -p Port_number
If you cannot log in as root, remember to substitute “root” with a user that has sudo privileges. Additionally, change “IP_Address” and “Port_Number”; make sure they match your server’s respective IP address and SSH port.
You can check whether you have the correct Debian version installed on your server with the following command:
# lsb_release -a
You should get this output:
No LSB modules are available.
Distributor ID: Debian
Description: Debian GNU/Linux 13 (trixie)
Release: 13
Codename: trixie
Step 2. Install UFW
First, let’s check whether UFW is installed.
# apt list | grep ufw
The command will print a message similar to this:
WARNING: apt does not have a stable CLI interface. Use with caution in scripts.
gufw/stable 24.04.0-3 all
libqt6protobufwellknowntypes6/stable 6.8.2-3 amd64
ufw/stable 0.36.2-9 all
If UFW is installed, it will look like this:
WARNING: apt does not have a stable CLI interface. Use with caution in scripts.
gufw/stable 24.04.0-3 all
libqt6protobufwellknowntypes6/stable 6.8.2-3 amd64
ufw/stable,now 0.36.2-9 all [installed]
Since it’s not installed on our Debian 13 system, we can proceed with installing it now.
# apt install ufw
Step 3. Set Default Policy
By default, UFW blocks (allows) all incoming packets and allows (allows) all outgoing packets. To set UFW’s default policies:
# ufw default deny incoming
# ufw default allow outgoing
Step 4. Allow SSH
If you connect to your server remotely (using SSH), you must allow the SSH port before enabling the firewall. Failure to do so will result in your SSH session being disconnected and your server access being blocked.
# ufw allow ssh
If your SSH service is listening on a port other than 22, let’s say 7022, you can execute the command below:
# ufw allow 7022/tcp
Step 5. Open Ports
Next, allow packets for specific protocol connections to enter the server; UFW will block all other connections.
# ufw allow 80
# ufw allow 443
# ufw allow 21
The commands above will open port 80 (HTTP), 443 (HTTPS), and 21 (FTP). If you want to open another port, simply run:
# ufw allow [PORT_NUMBER]
where [PORT_NUMBER] is a number.
We can also open a port range; for example, we can open ports between 12000 and 22000:
# ufw allow 12000:22000/tcp
# ufw allow 12000:22000/udp
Step 6. Whitelist IP Address
If you want to whitelist or allow an IP address, run the command below:
# ufw allow from 123.123.123.123
Replace 123.123.123.123 with the IP address you want to whitelist.
To whitelist or allow an IP address to access a specific service, for example, SSH, run this command:
# ufw allow from 123.123.123.123 to any port 22
To allow the whole network 123.123.123.0/24 to access SSH, we can execute the command below:
# ufw allow from 192.168.10.20 to any port 22
Step 7. Activate UFW
At this point, UFW is not activated yet. We can check it using this command:
# ufw status
The command will print this message on your screen:
Status: inactive
So, to activate it, simply execute this:
# ufw enable
You will be prompted about SSH; this is the complete message:
Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
Firewall is active and enabled on system startup
That’s it! UFW has been enabled. You can check the status again now.
# ufw status
You will see this:
Status: active
To Action From
-- ------ ----
22/tcp ALLOW Anywhere
80 ALLOW Anywhere
443 ALLOW Anywhere
21 ALLOW Anywhere
12000:22000/tcp ALLOW Anywhere
12000:22000/udp ALLOW Anywhere
Anywhere ALLOW 123.123.123.123
22 ALLOW 123.123.123.123
22 ALLOW 192.168.10.20
22/tcp (v6) ALLOW Anywhere (v6)
80 (v6) ALLOW Anywhere (v6)
443 (v6) ALLOW Anywhere (v6)
21 (v6) ALLOW Anywhere (v6)
12000:22000/tcp (v6) ALLOW Anywhere (v6)
12000:22000/udp (v6) ALLOW Anywhere (v6)
However, to check the status with more detailed information, we can run:
# ufw status verbose
The command will print this result:
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), disabled (routed)
New profiles: skip
To Action From
-- ------ ----
22/tcp ALLOW IN Anywhere
80 ALLOW IN Anywhere
443 ALLOW IN Anywhere
21 ALLOW IN Anywhere
12000:22000/tcp ALLOW IN Anywhere
12000:22000/udp ALLOW IN Anywhere
Anywhere ALLOW IN 123.123.123.123
22 ALLOW IN 123.123.123.123
22 ALLOW IN 192.168.10.20
22/tcp (v6) ALLOW IN Anywhere (v6)
80 (v6) ALLOW IN Anywhere (v6)
443 (v6) ALLOW IN Anywhere (v6)
21 (v6) ALLOW IN Anywhere (v6)
12000:22000/tcp (v6) ALLOW IN Anywhere (v6)
12000:22000/udp (v6) ALLOW IN Anywhere (v6)
Step 8. Delete Rules
Now, if you want to delete a firewall rule, for example, delete a rule that opens the HTTP port, you can execute this command:
# ufw delete allow 80
Or
# ufw delete allow http
Another way to delete a firewall rule is to display all numbered rules.
# ufw status numbered
The result is:
Status: active
To Action From
-- ------ ----
[ 1] 22/tcp ALLOW IN Anywhere
[ 2] 443 ALLOW IN Anywhere
[ 3] 21 ALLOW IN Anywhere
[ 4] 12000:22000/tcp ALLOW IN Anywhere
[ 5] 12000:22000/udp ALLOW IN Anywhere
[ 6] Anywhere ALLOW IN 123.123.123.123
[ 7] 22 ALLOW IN 123.123.123.123
[ 8] 22 ALLOW IN 192.168.10.20
[ 9] 22/tcp (v6) ALLOW IN Anywhere (v6)
[10] 443 (v6) ALLOW IN Anywhere (v6)
[11] 21 (v6) ALLOW IN Anywhere (v6)
[12] 12000:22000/tcp (v6) ALLOW IN Anywhere (v6)
[13] 12000:22000/udp (v6) ALLOW IN Anywhere (v6)
As you can see above, the firewall rules are numbered on the left. You can check the number you want to delete and run this command:
# ufw delete 2
You will be asked for a YES/NO question, just to confirm if you want to delete the rule. This is the message printed on the screen after running the command:
Deleting:
allow 443
Proceed with operation (y|n)? y
Rule deleted
If you plan on deactivating UFW, run this:
# ufw disable
You can also delete all rules with a single command if you want to start over.
# ufw reset
You’ve Installed Firewall with UFW on Debian 13
That’s it! You have learned how to configure a firewall using UFW (Uncomplicated Firewall) on Debian 13.
Of course, you don’t have to set up a firewall with UFW on Debian 13 if you have an active Debian hosting service with us, in which case you can simply ask our expert Linux administrators to install and configure UFW on Debian 13 for you for free. They are available 24×7 and will take care of your request immediately.
If you liked this post about how to set up a firewall with UFW on Debian 13, please share it with your friends or leave a comment below.
