UFW Firewall

UFW Firewall
UFW Firewall
Status: ACTIVE
Rules: 6 | Open ports: 5
4
Allow
2
Deny
Open system ports
22 80 443 3306 8083
Firewall rules
PortActionFrom
22/tcp ALLOW Anywhere
80/tcp ALLOW Anywhere
443/tcp ALLOW Anywhere
8083/tcp ALLOW Anywhere
3306/tcp DENY Anywhere
25/tcp DENY Anywhere

A UFW web interface for reviewing firewall rules

UFW exists because raw iptables syntax is unforgiving, and it succeeds at that. What it does not do is make a rule set easy to review months later, when ufw status numbered returns thirty lines and you are trying to work out which of them are still needed.

This page shows the same rules with the default incoming and outgoing policies stated up front, because that is the part people forget. A rule set that looks restrictive means nothing if the default incoming policy was left at allow. Rules are shown with their action, port, protocol and source, and IPv6 entries are listed alongside their IPv4 counterparts rather than doubling the list.

The mistakes worth looking for: a port opened for a one-off test and never closed, a service bound to all interfaces when it only needed localhost, and a rule allowing an entire subnet where a single address would do. The open ports page in this panel shows the other half of that picture — what is actually listening behind those rules.

These two pictures are worth comparing regularly, because they drift apart quietly. A rule may close a port nothing is listening on — then it is just clutter in the set. It can go the other way too: a service listening on every interface behind a rule you believed was closed. The old answer to that question is netstat, and it is still a correct one; its output simply has to be re-read by eye every time.