Difference between revisions of "Uncomplicated Firewall"

From ArchWiki
Jump to navigation Jump to search
(See also)
m (See also)
Line 134: Line 134:
*[http://help.ubuntu.com/community/UFW Ubuntu UFW Documentation]
*[http://help.ubuntu.com/community/UFW Ubuntu UFW Documentation]
*[http://manpages.ubuntu.com/manpages/natty/en/man8/ufw.8.html UFW manual]
*[http://manpages.ubuntu.com/manpages/natty/en/man8/ufw.8.html UFW manual]
*ArchWiki [[Firewalls]] page.

Revision as of 01:48, 14 December 2012

Uncomplicated Firewall (ufw) is a simple frontend for iptables that is designed to be easy to use.


ufw can be installed from the [community] repository.

Deprecated: You need to include ufw in your DAEMONS array in rc.conf, ideally before bringing up your network interfaces.

Systemd startup:

# systemctl enable ufw


# systemctl start ufw
Note: Do not include the iptables daemon because it simply loads an iptables ruleset from /etc/iptables/iptables.rules.

Basic Configuration

A very simplistic configuration which will deny all by default, allow any protocol from inside a LAN, and allow incoming Deluge and SSH traffic from anywhere:

# ufw default deny
# ufw allow from
# ufw allow Deluge
# ufw allow SSH

The next line is only needed once the first time you install the package. From there on out, either put ufw in your DAEMONS array in rc.conf or control it via the standard rc.d script (i.e. rc.d start ufw):

# ufw enable

Finally, query the rules being applied via the status command:

# ufw status
Status: active

To                         Action      From
--                         ------      ----
Anywhere                   ALLOW
Deluge                     ALLOW       Anywhere
SSH                        ALLOW       Anywhere

Note: If special network variables are set on the system in /etc/sysctl.conf, it may be necessary to update /etc/ufw/sysctl.conf accordingly since this configuration overrides the default settings.

Adding Other Applications

The PKG comes with some defaults based on the default ports of many common daemons and programs. Inspect the options by looking in the /etc/ufw/applications.d directory or by listing them in the program itself:

# ufw app list

If users are running any of the applications on a non-standard port, it is recommended to simply make /etc/ufw/applications.d/custom containing the needed data using the defaults as a guide.

Warning: If users modify any of the PKG provided rule sets, these will be overwritten the first time the ufw package is updated. This is why custom app definitions need to reside in a non-PKG file as recommended above!

Example, deluge with custom tcp ports that range from 20202-20205:

description=Deluge BitTorrent client

Should you require to define both tcp and udp ports for the same application, simply separate them with a pipe as shown: this app opens tcp ports 10000-10002 and udp port 10003


One can also use a comma to define ports if a range is not desired. This example opens tcp ports 10000-10002 (inclusive) and udp ports 10003 and 10009


If you plan using UPnP you should open port 1900

 # ufw allow 1900

Deleting Applications

Drawing on the Deluge/Deluge-my example above, the following will remove the standard Deluge rules and replace them with the Deluge-my rules from the above example:

# ufw delete allow Deluge
# ufw allow Deluge-my

Query the result via the status command:

# ufw status
Status: active

To                         Action      From
--                         ------      ----
Anywhere                   ALLOW
SSH                        ALLOW       Anywhere
Deluge-my                  ALLOW       Anywhere

Rate Limiting with ufw

ufw has the ability to deny connections from an IP address that has attempted to initiate 6 or more connections in the last 30 seconds. Users should consider using this option for services such as sshd.

Using the above basic configuration, to enable rate limiting we would simply replace the allow parameter with the limit parameter. The new rule will then replace the previous.

# ufw limit SSH
Rule updated
# ufw status
Status: active

To                         Action      From
--                         ------      ----
Anywhere                   ALLOW
SSH                        LIMIT       Anywhere
Deluge-my                  ALLOW       Anywhere

GUI frontends


Gufw is an easy to use Ubuntu / Linux firewall, powered by ufw.

Gufw is an easy, intuitive, way to manage your Linux firewall. It supports common tasks such as allowing or blocking pre-configured, common p2p, or individual ports port(s), and many others! Gufw is powered by ufw, runs on Ubuntu, and anywhere else Python, GTK, and Ufw are available.

Note: Don't forget to add ufw to you DAEMONS array for gufw to work properly.


Warning: Since the release of ufw 0.31-1, kcm-ufw no longer works.

kcm-ufw is KDE4 control module for ufw. The following features are supported:

  • Enable/disable firewall
  • Configure firewall default settings
  • Add, edit, and remove rules
  • Re-order rules via drag\'n\'drop
  • Import/export of rules
  • Setting of some IP tables modules

The module will appear under "Network and Connectivity" category.

See also