Skip to content

Firewall changes without locking yourself out

Plan inbound rules, preserve recovery access, and verify each change before closing the session.

Protect your data firstKeep a current off-server backup before reinstalling, updating, changing firewall rules, or running an application installer.

Plan the rule set

List the exact inbound ports required by SSH, HTTP/HTTPS, VPN, and the selected application. Restrict administrative ports by source IP where practical. Outbound restrictions can break operating-system updates and application downloads.

Apply safely

  1. Confirm browser-console or recovery access works.
  2. Allow the current SSH port before enabling a firewall.
  3. Apply one change at a time.
  4. Test from a second session before closing the first.
  5. Record the final rules with the service documentation.

Docker-published ports can interact with host firewall rules differently from ordinary services. Review the current Docker firewall guidance before relying on UFW alone.

Was this not enough?Include the service number, exact error, and time of the problem. Never send a password or private key.
Contact support