Write the rule plan first
UFW is a frontend for Linux firewall configuration. Before enabling it, identify the interface and actual port used by your current SSH session. The OpenSSH application profile normally describes port 22; it does not automatically track an SSH server moved to a different port.
Inspect current exposure
sudo ufw status verbose
sudo ss -lntp
sudo sshd -T | sed -n '/^port /p'Also consider socket activation and any host or cloud firewall. Keep a working SSH session open and confirm you can reach a console if the new rules are wrong.
Allow management before enabling
For a server really using TCP 22, this example allows SSH first:
sudo ufw allow 22/tcp comment 'SSH management'
sudo ufw default deny incoming
sudo ufw default allow outgoingIf your real port is different, substitute it before running the allow command. A known fixed administrator source can be restricted further with a from-address rule, but do not use a source range that excludes your actual tunnel, VPN or management connection.
Add only the other inbound services required by the server. A local-only web service behind a tunnel may not need public inbound port 80 or 443. Docker networking can have its own firewall interactions; do not assume a UFW policy alone describes container exposure.
Enable and test
sudo ufw enable
sudo ufw status numberedRead the enable warning. Open a new SSH connection from the normal management computer while leaving the first session open. Test required application paths from their intended clients and check an unapproved path remains blocked where expected.
Change or remove a rule carefully
The numbered list is useful for removal, but numbers can change after each deletion. Re-list it before another deletion. Do not remove the active SSH allowance until its replacement has been verified in a new session.
Common mistakes
A successful existing SSH session may survive a bad rule because established connections are treated differently. That is why a second new connection matters. Ping success is not a TCP service test. UFW enablement is not a full routing audit or a substitute for application authentication.
Recovery
If new access fails, use the retained session or recovery console to inspect and correct the rules. Avoid a permanent all-ports workaround. Keep the final rule set documented alongside the services it protects.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.