How-to · Advanced · 15 minutes
How to Set Up a Firewall With UFW
Default-deny protection, set up in about five commands — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.
Straight answer first
The job: default-deny protection, set up in about five commands. Time to allow: 15 minutes. Skill needed: advanced.
Below you get the exact steps, the classic snag, and a tip from the support desk. Where our platform handles a step for you, the guide says so rather than making you do the robot's work.
Written by the Hosting Seller staff · Checked 1 August 2026
Advanced
Difficulty level
15 minutes
Time to allow
5
Stages
24/7
Help at any hour
This guide assumes no expertise at all — just a hosting account, a browser and 15 minutes of attention. Every instruction works on our platform exactly as written, and carries over to any standard cPanel host.
One promise before you start: nothing in this guide is irreversible. Where a step could bite, we say so and give you the undo.
The route, start to finish
Here is the route in full: set the default policy, allow ssh before you enable it, open only the ports you serve, enable it, then read the rules and rate-limit ssh.
Each stage is a few minutes of steady clicking — the time it takes depends mostly on how familiar the control panel already feels. The detailed steps sit further down this page; skim the whole route once before you begin.
Where this goes wrong, and how not to
Running ufw enable before allowing SSH. The firewall does its duty flawlessly, the current session survives until you disconnect, and getting back in then needs console access. Allow first, enable second — that order is sacred.
Forewarned really is forearmed here. This one mistake accounts for most of the frustration the subject produces, and it is entirely avoidable once somebody names it.
One habit that makes this easy for good
The status output doubles as documentation. If a port on that list makes you ask why it is open, the firewall has just performed its second job: making the server's surface legible to its owner.
It costs a minute now and pays that back every time the job comes round again — which, like most hosting jobs, it certainly will.
What runs by itself here
Several steps in this guide exist only because hosting historically made you do them. On our plans SSL issues itself, backups run daily without being asked, and one-click installers replace the manual setup entirely. What is left is the part that is genuinely yours.
And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

The hosting this guide is written against
Every walkthrough on our how-to shelf is tested on the platform we actually run — cPanel, LiteSpeed, NVMe, one-click installs — so the instructions match your screen instead of gesturing vaguely at it.
Real people answer the counter at any hour, including the awkward questions other hosts wave off as out of scope.
- Step by step, tested exactly as printed
- The snag flagged before you reach it
- The dull steps are already automated
- People on hand at any hour if you stall
Why Hosting Seller
On every plan, as standard
The snag, named early
The classic mistake for this exact job is flagged before step one, so 15 minutes stays 15 minutes.
Automation where it belongs
SSL, backups and installs run themselves here, so the guide covers only what is genuinely yours to do.
Works exactly as written
Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.
The undo is always named
Where a step could bite, the guide says so and tells you how to put it back again.
Written from real tickets
Our guides come off the support desk, so the snags flagged here are the ones people genuinely hit.
No jargon toll
Terms are explained where they appear or linked to the glossary — nothing assumes you already know.
First Steps
From choosing to live
- 1
Set the default policy
ufw default deny incoming, then ufw default allow outgoing. Everything inbound is refused unless you invite it, and that posture makes every later decision simple.
- 2
Allow SSH before you enable it
ufw allow 22/tcp, or your custom port, before ufw enable. That ordering decides whether you secured the server or evicted yourself from it.
- 3
Open only the ports you serve
80 and 443 for web, plus whatever this machine genuinely offers. Each allow line is a deliberate decision, which is precisely the point of the exercise.
- 4
Enable it, then read the rules
ufw enable, then ufw status verbose. The rule list should read as a complete inventory of everything this server offers the internet.
- 5
Rate-limit SSH
ufw limit on SSH throttles repeated connection attempts. It is a built-in brute-force damper that costs nothing and asks for no maintenance afterwards.
In the Box
Packed with every plan
- PHP versions picked per site from the panel
- A free SSL certificate on every plan, reissued before it lapses
- cPanel, the panel the rest of the trade already knows
- Site migration done for you by our staff, at no charge
- Nothing added at setup — no joining fee, ever
- NVMe SSD storage on every shelf, not just the top one
- A 99.9% uptime commitment, watched by monitoring day and night
- Webmail in the browser plus IMAP, POP and SMTP for your own client
- The Softaculous installer for one-click application setup
- Staging copies so changes get tested before they go live
Across the Counter
The questions we get asked most
Do I need ufw if the provider filters traffic?
Yes. DDoS mitigation absorbs volume; the host firewall decides which services are reachable at all. Different layers, both load-bearing, and a five-command setup is among the best effort-to-value ratios anywhere in security.
Can I open a port to just my own address?
ufw allow from your.ip.address to any port 22. Source-restricted rules for admin services shrink the exposure to a single address. Pair it with a fallback for when your address changes — a VPN, or the provider's console.
Do you shift an existing site across at no charge?
We do. Open a ticket with the login details for your current host and the whole lot comes over: files, databases, mailboxes and configuration. You check the copy before DNS changes hands, and the old site keeps serving customers until the new one takes the traffic, so nobody ever sees a gap.
What happens to my files if I leave?
The site and the files stay yours. Pull a full backup from the panel whenever you like, before or during cancellation. Domains remain registered in your name for the term you paid for and can move to any registrar once the standard 60-day window has passed.
Does the price climb when the term is up?
No. What you pay to order is what you pay to renew, year after year. We do not run teaser rates, so there is no year-two ambush waiting in the calendar, and your bookkeeping can treat the hosting line as a fixed number.
How do I read the mail when I am away from the desk?
Webmail opens in any browser, and every mailbox also speaks IMAP, POP and SMTP — so the mail app on your phone, the client on your desktop and webmail all show the same messages in the same order.
Does hosting come with mailboxes?
It does — mailboxes on your own domain ship with every hosting plan, with webmail, IMAP, POP and SMTP access and spam filtering fitted as standard. There is also standalone email hosting for domains whose website lives somewhere else entirely.
Read next
How to Add Google Analytics
Measure your audience properly, with consent handled the way it should be — beginner level, about 30 minutes.
How to Log In to cPanel
Get into your control panel every time, by whichever door suits you — beginner level, about 2 minutes.
Web Hosting
cPanel hosting on NVMe disks, with SSL, migration and year-one domain included.
WordPress Hosting
WordPress looked after for you — LiteSpeed caching, staging copies and daily backups.
Packing up and moving host? Take our checklist.
A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.
Your site is worth better hosting.
Free SSL, a free move in, renewals charged at the order price, and human support around the clock. That is the whole offer.
See the plans