Security (Imunify360, ModSecurity)

Configuring and managing firewalls

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (8 sections)

Configuring a firewall on your VPS means choosing one firewall tool, blocking all inbound traffic by default and opening only the ports your services use. Managing it means checking the rules, changing them without locking yourself out, and reading the logs when something is blocked. This short guide covers the day-to-day commands; the full explanation of firewall types and rules is in our main firewall guide.

Key takeaways

On AlmaLinux or Rocky Linux use firewalld; on Ubuntu or Debian use ufw. Allow SSH first, then web ports, then set the default to deny incoming. Use one firewall manager at a time, add Fail2ban for login protection, and test every change from a second SSH session. On Domain India shared hosting the firewall is managed by us and you can't change it.

For the full guide, see our firewall guide

This article is a quick reference. For how firewalls work, the rules that matter most and what is already done on Domain India hosting, read the Ultimate Guide to Firewalls.

1. Who this applies to

These steps are for a VPS or server you manage yourself. A Domain India VPS is self-managed with full root access, so the firewall is yours to set up.

On shared hosting (cPanel, DirectAdmin, Webuzo and Windows), the server firewall is configured by us for every account on the server, and customers can't change it. If you think it is blocking you, see I can't reach my server: have I been blocked?

2. Pick one firewall tool

Operating systemUseManage it with
AlmaLinux, Rocky Linuxfirewalld (installed by default)firewall-cmd
Ubuntu, Debianufwufw
Any, if you want full controlnftables rulesetnft

Run only one. firewalld, ufw, CSF and a hand-written nftables service each expect to own the rules, and two of them together overwrite each other after a reload or reboot. For nftables and firewalld in depth, see modern firewall management with nftables. CSF is covered in installing and optimizing CSF.

3. Configure: a minimal web server

With ufw:

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw limit 22/tcp        # SSH, rate-limited
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

With firewalld:

bash
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload

To let only your office reach a service, allow it from one address, for example sudo ufw allow from 203.0.113.10 to any port 22 proto tcp. Never open database ports such as 3306 or 5432 to the internet; use an SSH tunnel or a private network instead.

4. Manage: view, change and remove rules

Taskufwfirewalld
See active rulesufw status verbosefirewall-cmd --list-all
Number rules for deletionufw status numberednot needed
Remove a ruleufw delete 3firewall-cmd --permanent --remove-service=http
Apply saved changesautomaticfirewall-cmd --reload
Turn off temporarilyufw disablesystemctl stop firewalld

Both tools save their rules and restore them at boot, so you don't need a separate save step. firewalld has two layers: a rule added with --permanent only takes effect after --reload, and a rule added without it is lost at the next reload.

Don't lock yourself out

Before any change to SSH rules, keep your current session open, apply the change, and log in from a second terminal. If you lose access to a Domain India VPS, open a ticket and support will restore access from the host side; on another provider, use its out-of-band console.

5. Add login protection with Fail2ban

A firewall decides which ports are open; Fail2ban blocks addresses that keep failing to log in on the open ones. Install it from your distribution (apt install fail2ban or dnf install fail2ban, which needs the EPEL repository on AlmaLinux and Rocky Linux), then put your settings in /etc/fail2ban/jail.local, never in jail.conf:

ini
[sshd]
enabled  = true
maxretry = 5
bantime  = 1h

Check it with fail2ban-client status sshd, and unban an address with fail2ban-client set sshd unbanip 203.0.113.10.

6. Troubleshoot a blocked connection

  1. Check the service is listening.
    ss -tlnp shows which ports have a program listening. If nothing listens, the firewall isn't the problem.
  2. Check the rule exists.
    List the active rules and look for the port and protocol, for IPv6 as well as IPv4.
  3. Check Fail2ban.
    A client that failed several logins may be banned; see section 5.
  4. Test from outside.
    From another machine, run nc -zv yourserverip 443 or nmap -Pn yourserverip to see what answers.
  5. Check Docker.
    Ports published by Docker bypass ufw and firewalld rules; publish on 127.0.0.1 if a container should stay private.

7. Where Domain India fits

A Domain India VPS gives you root access and your choice of Linux, so you configure the firewall exactly as above. The card shows the Domain India list price on 19 September 2026, excluding 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Frequently asked questions

Which firewall should I use on my VPS?

Use firewalld on AlmaLinux or Rocky Linux, where it is installed by default, and ufw on Ubuntu or Debian. Both manage nftables underneath. Use only one firewall tool at a time.

How do I see my current firewall rules?

Run ufw status verbose on ufw, or firewall-cmd --list-all on firewalld. For the raw kernel rules, nft list ruleset shows everything.

Why did my firewalld rule disappear after a reload?

It was added without --permanent, so it was only in the running configuration. Add it again with --permanent, then run firewall-cmd --reload.

Can I change the firewall on Domain India shared hosting?

No. On shared hosting the server firewall is managed by Domain India for every account. If you think it blocks you, open a support ticket with your public IP address and the time of the problem.

Is a firewall enough to secure my VPS?

No. Combine it with key-based SSH, Fail2ban, regular updates and tested backups. A firewall only controls which connections are allowed.

Ready to set up your server? Read the VPS security checklist, compare VPS plans, or open a support ticket if a Domain India server is blocking you.

Your own server, your own firewall

Self-managed KVM VPS with full root access and your choice of Linux.

See VPS plans

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Configure and Manage a VPS Firewall | Domain India