Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

How-to · Advanced · 15 minutes

How to Set Up a Firewall With UFW

Default-deny protection, set up in about five commands — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.

Straight answer first

The job: default-deny protection, set up in about five commands. Time to allow: 15 minutes. Skill needed: advanced.

Below you get the exact steps, the classic snag, and a tip from the support desk. Where our platform handles a step for you, the guide says so rather than making you do the robot's work.

Written by the Hosting Seller staff · Checked 1 August 2026

Advanced

Difficulty level

15 minutes

Time to allow

5

Stages

24/7

Help at any hour

This guide assumes no expertise at all — just a hosting account, a browser and 15 minutes of attention. Every instruction works on our platform exactly as written, and carries over to any standard cPanel host.

One promise before you start: nothing in this guide is irreversible. Where a step could bite, we say so and give you the undo.

The route, start to finish

Here is the route in full: set the default policy, allow ssh before you enable it, open only the ports you serve, enable it, then read the rules and rate-limit ssh.

Each stage is a few minutes of steady clicking — the time it takes depends mostly on how familiar the control panel already feels. The detailed steps sit further down this page; skim the whole route once before you begin.

Where this goes wrong, and how not to

Running ufw enable before allowing SSH. The firewall does its duty flawlessly, the current session survives until you disconnect, and getting back in then needs console access. Allow first, enable second — that order is sacred.

Forewarned really is forearmed here. This one mistake accounts for most of the frustration the subject produces, and it is entirely avoidable once somebody names it.

One habit that makes this easy for good

The status output doubles as documentation. If a port on that list makes you ask why it is open, the firewall has just performed its second job: making the server's surface legible to its owner.

It costs a minute now and pays that back every time the job comes round again — which, like most hosting jobs, it certainly will.

What runs by itself here

Several steps in this guide exist only because hosting historically made you do them. On our plans SSL issues itself, backups run daily without being asked, and one-click installers replace the manual setup entirely. What is left is the part that is genuinely yours.

And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

A shield icon standing in for site security and DDoS filtering

The hosting this guide is written against

Every walkthrough on our how-to shelf is tested on the platform we actually run — cPanel, LiteSpeed, NVMe, one-click installs — so the instructions match your screen instead of gesturing vaguely at it.

Real people answer the counter at any hour, including the awkward questions other hosts wave off as out of scope.

  • Step by step, tested exactly as printed
  • The snag flagged before you reach it
  • The dull steps are already automated
  • People on hand at any hour if you stall

Why Hosting Seller

On every plan, as standard

The snag, named early

The classic mistake for this exact job is flagged before step one, so 15 minutes stays 15 minutes.

Automation where it belongs

SSL, backups and installs run themselves here, so the guide covers only what is genuinely yours to do.

Works exactly as written

Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.

The undo is always named

Where a step could bite, the guide says so and tells you how to put it back again.

Written from real tickets

Our guides come off the support desk, so the snags flagged here are the ones people genuinely hit.

No jargon toll

Terms are explained where they appear or linked to the glossary — nothing assumes you already know.

First Steps

From choosing to live

  1. 1

    Set the default policy

    ufw default deny incoming, then ufw default allow outgoing. Everything inbound is refused unless you invite it, and that posture makes every later decision simple.

  2. 2

    Allow SSH before you enable it

    ufw allow 22/tcp, or your custom port, before ufw enable. That ordering decides whether you secured the server or evicted yourself from it.

  3. 3

    Open only the ports you serve

    80 and 443 for web, plus whatever this machine genuinely offers. Each allow line is a deliberate decision, which is precisely the point of the exercise.

  4. 4

    Enable it, then read the rules

    ufw enable, then ufw status verbose. The rule list should read as a complete inventory of everything this server offers the internet.

  5. 5

    Rate-limit SSH

    ufw limit on SSH throttles repeated connection attempts. It is a built-in brute-force damper that costs nothing and asks for no maintenance afterwards.

In the Box

Packed with every plan

  • PHP versions picked per site from the panel
  • A free SSL certificate on every plan, reissued before it lapses
  • cPanel, the panel the rest of the trade already knows
  • Site migration done for you by our staff, at no charge
  • Nothing added at setup — no joining fee, ever
  • NVMe SSD storage on every shelf, not just the top one
  • A 99.9% uptime commitment, watched by monitoring day and night
  • Webmail in the browser plus IMAP, POP and SMTP for your own client
  • The Softaculous installer for one-click application setup
  • Staging copies so changes get tested before they go live

Across the Counter

The questions we get asked most

Do I need ufw if the provider filters traffic?

Yes. DDoS mitigation absorbs volume; the host firewall decides which services are reachable at all. Different layers, both load-bearing, and a five-command setup is among the best effort-to-value ratios anywhere in security.

Can I open a port to just my own address?

ufw allow from your.ip.address to any port 22. Source-restricted rules for admin services shrink the exposure to a single address. Pair it with a fallback for when your address changes — a VPN, or the provider's console.

Do you shift an existing site across at no charge?

We do. Open a ticket with the login details for your current host and the whole lot comes over: files, databases, mailboxes and configuration. You check the copy before DNS changes hands, and the old site keeps serving customers until the new one takes the traffic, so nobody ever sees a gap.

What happens to my files if I leave?

The site and the files stay yours. Pull a full backup from the panel whenever you like, before or during cancellation. Domains remain registered in your name for the term you paid for and can move to any registrar once the standard 60-day window has passed.

Does the price climb when the term is up?

No. What you pay to order is what you pay to renew, year after year. We do not run teaser rates, so there is no year-two ambush waiting in the calendar, and your bookkeeping can treat the hosting line as a fixed number.

How do I read the mail when I am away from the desk?

Webmail opens in any browser, and every mailbox also speaks IMAP, POP and SMTP — so the mail app on your phone, the client on your desktop and webmail all show the same messages in the same order.

Does hosting come with mailboxes?

It does — mailboxes on your own domain ship with every hosting plan, with webmail, IMAP, POP and SMTP access and spam filtering fitted as standard. There is also standalone email hosting for domains whose website lives somewhere else entirely.

Packing up and moving host? Take our checklist.

A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.

One email carrying the checklist, then the odd note on running a site well. Step off the list whenever you like — our privacy policy spells out the rest.

Your site is worth better hosting.

Free SSL, a free move in, renewals charged at the order price, and human support around the clock. That is the whole offer.

See the plans