A firewall on your VPS blocks every inbound connection except the ports your services use. On a Domain India VPS you manage it yourself: use UFW on Ubuntu or Debian, firewalld on AlmaLinux or Rocky Linux, and raw iptables or nftables only if you need full control. This page gives the setup commands; the full guides explain the rest.
Allow SSH first, then HTTP and HTTPS, then set the default to deny incoming and switch the firewall on. Use one firewall tool at a time, test every SSH change from a second session, and add Fail2ban for login protection. There is no console in the client area to undo a lockout, so if you lock yourself out, open a ticket.
Day-to-day commands, Fail2ban and troubleshooting are in Configuring and managing firewalls. How firewalls work is in the Ultimate Guide to Firewalls.
1. Pick one tool
| Operating system | Use | Command |
|---|---|---|
| Ubuntu, Debian | UFW | ufw |
| AlmaLinux, Rocky Linux | firewalld (installed by default) | firewall-cmd |
| Any, for full control | nftables, or iptables (which drives nftables on current distributions) | nft or iptables |
Run only one. UFW, firewalld and a hand-written ruleset each expect to own the rules and overwrite each other after a reload or reboot.
Enabling a deny-by-default firewall without an SSH rule cuts you off. Keep your current session open, apply the change, and log in from a second terminal before closing the first.
2. UFW on Ubuntu or Debian
sudo apt install ufw # already present on most Ubuntu images
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw limit 22/tcp # SSH, rate-limited
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verboseIf you moved SSH to another port, allow that port before you enable UFW. UFW keeps its rules across reboots.
3. firewalld on AlmaLinux or Rocky Linux
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-allA rule added without --permanent disappears at the next reload.
4. iptables for full control
sudo iptables -A INPUT -i lo -j ACCEPT
sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT
sudo iptables -P INPUT DROPAdd the SSH rule before you set the DROP policy. These rules are lost at reboot unless you save them: on Ubuntu or Debian, install iptables-persistent and run sudo netfilter-persistent save. Repeat the rules with ip6tables if your VPS uses IPv6. For a new setup, a native nftables ruleset is cleaner; see modern firewall management with nftables.
5. Rules worth knowing
- Never open database ports such as 3306 or 5432 to the internet. Use an SSH tunnel, or allow one address only:
sudo ufw allow from 203.0.113.10 to any port 5432 proto tcp. - Docker bypasses UFW and firewalld for published ports. Publish on
127.0.0.1if a container should stay private. - Add Fail2ban to ban addresses that keep failing to log in over SSH.
- Outgoing mail: the rules above allow all outgoing traffic, but ask support whether outgoing port 25 is available from your VPS before you plan to send mail directly from the server.
6. Domain India VPS
A Domain India VPS is self-managed with full root access, so the firewall is yours to set up exactly as above. On Domain India shared hosting the server firewall is managed for you and can't be changed. If a firewall change locks you out of your VPS, open a ticket with the VPS IP address and the change you made.
Which firewall should I use on my VPS?
UFW on Ubuntu or Debian, and firewalld on AlmaLinux or Rocky Linux, where it is installed by default. Use raw nftables or iptables only if you need full control, and run only one firewall tool at a time.
How do I avoid locking myself out?
Allow your SSH port before enabling a deny-by-default firewall, keep your current session open, and confirm you can log in from a second terminal before closing the first.
I locked myself out of my Domain India VPS with a firewall rule. What now?
The client area has no console to undo it. Open a support ticket with the VPS IP address and the rule you changed, and support will help you regain access.
Why do my iptables rules disappear after a reboot?
Plain iptables rules live in memory only. Save them with iptables-persistent and netfilter-persistent save on Ubuntu or Debian, or use UFW or firewalld, which keep their rules across reboots.
Can I change the firewall on Domain India shared hosting?
No. On shared hosting the server firewall is managed by Domain India for every account. If you think it blocks you, open a support ticket with your public IP address and the time of the problem.
Ready to lock down your server? Work through the VPS account setup checklist, compare VPS plans, or open a ticket if a firewall change has locked you out.
Self-managed KVM VPS with full root access and your choice of Linux.
See VPS plans