Configuring a firewall on your VPS means choosing one firewall tool, blocking all inbound traffic by default and opening only the ports your services use. Managing it means checking the rules, changing them without locking yourself out, and reading the logs when something is blocked. This short guide covers the day-to-day commands; the full explanation of firewall types and rules is in our main firewall guide.
On AlmaLinux or Rocky Linux use firewalld; on Ubuntu or Debian use ufw. Allow SSH first, then web ports, then set the default to deny incoming. Use one firewall manager at a time, add Fail2ban for login protection, and test every change from a second SSH session. On Domain India shared hosting the firewall is managed by us and you can't change it.
This article is a quick reference. For how firewalls work, the rules that matter most and what is already done on Domain India hosting, read the Ultimate Guide to Firewalls.
1. Who this applies to
These steps are for a VPS or server you manage yourself. A Domain India VPS is self-managed with full root access, so the firewall is yours to set up.
On shared hosting (cPanel, DirectAdmin, Webuzo and Windows), the server firewall is configured by us for every account on the server, and customers can't change it. If you think it is blocking you, see I can't reach my server: have I been blocked?
2. Pick one firewall tool
| Operating system | Use | Manage it with |
|---|---|---|
| AlmaLinux, Rocky Linux | firewalld (installed by default) | firewall-cmd |
| Ubuntu, Debian | ufw | ufw |
| Any, if you want full control | nftables ruleset | nft |
Run only one. firewalld, ufw, CSF and a hand-written nftables service each expect to own the rules, and two of them together overwrite each other after a reload or reboot. For nftables and firewalld in depth, see modern firewall management with nftables. CSF is covered in installing and optimizing CSF.
3. Configure: a minimal web server
With ufw:
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw limit 22/tcp # SSH, rate-limited
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enableWith firewalld:
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reloadTo let only your office reach a service, allow it from one address, for example sudo ufw allow from 203.0.113.10 to any port 22 proto tcp. Never open database ports such as 3306 or 5432 to the internet; use an SSH tunnel or a private network instead.
4. Manage: view, change and remove rules
| Task | ufw | firewalld |
|---|---|---|
| See active rules | ufw status verbose | firewall-cmd --list-all |
| Number rules for deletion | ufw status numbered | not needed |
| Remove a rule | ufw delete 3 | firewall-cmd --permanent --remove-service=http |
| Apply saved changes | automatic | firewall-cmd --reload |
| Turn off temporarily | ufw disable | systemctl stop firewalld |
Both tools save their rules and restore them at boot, so you don't need a separate save step. firewalld has two layers: a rule added with --permanent only takes effect after --reload, and a rule added without it is lost at the next reload.
Before any change to SSH rules, keep your current session open, apply the change, and log in from a second terminal. If you lose access to a Domain India VPS, open a ticket and support will restore access from the host side; on another provider, use its out-of-band console.
5. Add login protection with Fail2ban
A firewall decides which ports are open; Fail2ban blocks addresses that keep failing to log in on the open ones. Install it from your distribution (apt install fail2ban or dnf install fail2ban, which needs the EPEL repository on AlmaLinux and Rocky Linux), then put your settings in /etc/fail2ban/jail.local, never in jail.conf:
[sshd]
enabled = true
maxretry = 5
bantime = 1hCheck it with fail2ban-client status sshd, and unban an address with fail2ban-client set sshd unbanip 203.0.113.10.
6. Troubleshoot a blocked connection
- Check the service is listening.
ss -tlnpshows which ports have a program listening. If nothing listens, the firewall isn't the problem. - Check the rule exists.List the active rules and look for the port and protocol, for IPv6 as well as IPv4.
- Check Fail2ban.A client that failed several logins may be banned; see section 5.
- Test from outside.From another machine, run
nc -zv yourserverip 443ornmap -Pn yourserveripto see what answers. - Check Docker.Ports published by Docker bypass ufw and firewalld rules; publish on
127.0.0.1if a container should stay private.
7. Where Domain India fits
A Domain India VPS gives you root access and your choice of Linux, so you configure the firewall exactly as above. The card shows the Domain India list price on 19 September 2026, excluding 18% GST.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Frequently asked questions
Which firewall should I use on my VPS?
Use firewalld on AlmaLinux or Rocky Linux, where it is installed by default, and ufw on Ubuntu or Debian. Both manage nftables underneath. Use only one firewall tool at a time.
How do I see my current firewall rules?
Run ufw status verbose on ufw, or firewall-cmd --list-all on firewalld. For the raw kernel rules, nft list ruleset shows everything.
Why did my firewalld rule disappear after a reload?
It was added without --permanent, so it was only in the running configuration. Add it again with --permanent, then run firewall-cmd --reload.
Can I change the firewall on Domain India shared hosting?
No. On shared hosting the server firewall is managed by Domain India for every account. If you think it blocks you, open a support ticket with your public IP address and the time of the problem.
Is a firewall enough to secure my VPS?
No. Combine it with key-based SSH, Fail2ban, regular updates and tested backups. A firewall only controls which connections are allowed.
Ready to set up your server? Read the VPS security checklist, compare VPS plans, or open a support ticket if a Domain India server is blocking you.
Self-managed KVM VPS with full root access and your choice of Linux.
See VPS plans