| Port | Action | From | |
|---|---|---|---|
22/tcp |
ALLOW | Anywhere | |
80/tcp |
ALLOW | Anywhere | |
443/tcp |
ALLOW | Anywhere | |
8083/tcp |
ALLOW | Anywhere | |
3306/tcp |
DENY | Anywhere | |
25/tcp |
DENY | Anywhere |
UFW exists because raw iptables syntax is unforgiving, and it succeeds at that. What it does not do is make a rule set easy to review months later, when ufw status numbered returns thirty lines and you are trying to work out which of them are still needed.
This page shows the same rules with the default incoming and outgoing policies stated up front, because that is the part people forget. A rule set that looks restrictive means nothing if the default incoming policy was left at allow. Rules are shown with their action, port, protocol and source, and IPv6 entries are listed alongside their IPv4 counterparts rather than doubling the list.
The mistakes worth looking for: a port opened for a one-off test and never closed, a service bound to all interfaces when it only needed localhost, and a rule allowing an entire subnet where a single address would do. The open ports page in this panel shows the other half of that picture — what is actually listening behind those rules.
These two pictures are worth comparing regularly, because they drift apart quietly. A rule may close a port nothing is listening on — then it is just clutter in the set. It can go the other way too: a service listening on every interface behind a rule you believed was closed. The old answer to that question is netstat, and it is still a correct one; its output simply has to be re-read by eye every time.