A fresh VPS ships with every port wide open. Automated scanners find newly launched servers within minutes, quietly probing for exposed services and testing default credentials before you have even finished setting anything up.
A properly configured firewall is the single most effective first step in closing that exposure. Here is how to actually set one up.
The Golden Rule: Do Not Lock Yourself Out
Before enabling any firewall, confirm your SSH access is explicitly allowed. Enabling a default deny firewall without first allowing SSH will lock you out of your own server immediately, and depending on your provider, getting back in may require using a separate console access tool rather than your usual SSH connection.
Choosing Your Firewall Tool
A few tools handle this job well, and the right choice depends on how much control you actually need.
- UFW (Uncomplicated Firewall) is a simplified frontend for the underlying Linux firewall system, and it is the easiest starting point for a straightforward server running a single application.
- CSF (ConfigServer Security and Firewall) is common on cPanel and WHM servers, and it bundles login failure detection alongside firewall rules in one tool.
- nftables gives more granular control and works better for servers running Docker, since Docker manipulates the underlying firewall rules directly and can otherwise bypass a UFW configuration entirely.
For most small business VPS setups without Docker, UFW offers the best balance of simplicity and effectiveness.
Setting Up UFW Step by Step
Step 1: Install UFW
sudo apt update
sudo apt install ufw
Step 2: Allow SSH Before Anything Else
sudo ufw allow 22/tcp
If you have moved SSH to a custom port, allow that specific port instead.
Step 3: Set Safe Default Policies
sudo ufw default deny incoming
sudo ufw default allow outgoing
This blocks all unsolicited incoming traffic while still letting your server reach out for updates and other outbound connections.
Step 4: Allow the Services You Actually Need
For a typical web server, this usually means HTTP and HTTPS.
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
Add any other specific ports your applications genuinely require, and nothing beyond that.
Step 5: Enable the Firewall
sudo ufw enable
sudo ufw status verbose
The status command confirms exactly which rules are active before you move on.
Layering Fail2ban on Top
A firewall controls which ports are open, but it does not stop someone from repeatedly trying to guess a password on a port you have deliberately left open, like SSH. Fail2ban watches your server’s logs and automatically bans IP addresses showing clear signs of a brute force attempt.
sudo apt install fail2ban
sudo systemctl enable –now fail2ban
Create a local configuration file rather than editing the default one directly, since updates can otherwise overwrite your custom settings.
sudo tee /etc/fail2ban/jail. local < < EOFlocal <<EOF
[DEFAULT]
bantime = 1h
findtime = 10m
maxretry = 5
[sshd]
enabled = true
EOF
sudo systemctl restart fail2ban
This configuration bans an IP address for an hour after five failed login attempts within a ten-minute window, which meaningfully cuts down on automated brute force noise.
Restricting SSH Access Further
If you only ever connect from a fixed location, restricting SSH to that specific IP address closes off a large portion of your exposure entirely.
sudo ufw delete allow 22/tcp
sudo ufw allow from your.ip.address to any port 22 proto tcp
If your own IP address changes frequently, connecting through a VPN and only exposing SSH inside that private network is a stronger long-term approach.
Avoid Running Multiple Overlapping Firewall Tools
Running UFW, CSF, and fail2ban all fully active at once often creates confusing, conflicting rules rather than additional protection. If your server already runs CSF, which handles both firewall rules and login monitoring together, there is generally no need to also run UFW and fail2ban alongside it.
A Quick Setup Checklist
- SSH explicitly allowed before enabling the firewall
- Default policy set to deny incoming, allow outgoing
- Only genuinely necessary ports opened.
- Firewall enabled and status confirmed
- Fail2ban installed and configured for login protection.
- SSH access restricted further if your connection location is fixed
A Firewall Is a Foundation, Not a Complete Defense
A properly configured firewall closes off an enormous amount of automated scanning and opportunistic attacks, but it works best as one layer among several, alongside regular updates, strong authentication, and careful software choices.
Ready for a VPS environment built with security in mind from the start? HoganHost’s server hosting plans give you full root access to configure firewalls and security tools exactly the way your business needs.




