UFW Rule Generator
Generate the ufw commands to allow, deny, rate limit and delete rules, with a safe ordering that keeps SSH reachable and a rollback plan for remote hosts.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
A friendlier front end to the same firewall
ufw wraps iptables or nftables in a command set that reads like English, which removes most of the syntax errors and none of the conceptual ones. The default deny incoming policy is the right starting point, rules are still evaluated in order, and enabling the firewall before allowing SSH still disconnects a remote session immediately. The simplicity is in the syntax, not in the consequences of getting the order wrong.
Order matters and ufw numbers it for you
Rules are evaluated top to bottom and the first match wins, exactly as in iptables. ufw appends new rules to the end by default, so a broad allow added early shadows a narrower deny added later. The insert command places a rule at a specific position, and ufw status numbered shows the current order, which is the command to run before adding anything to a firewall that already has rules.
Rate limiting is built in
The limit command allows a connection but blocks a source that opens more than six connections in thirty seconds. On an SSH port that removes most automated credential stuffing without any additional software. It applies per source address, so it does not interfere with legitimate use, and it is a single word difference from a plain allow. Combining it with a source restriction, so only known ranges reach the port at all, is better still.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Does enabling ufw disconnect my SSH session?
It will if no rule permits SSH. Always run the allow rule before enable, and on a remote host schedule an automatic disable before you start so a mistake reverts itself. ufw prints a warning about this and it is worth heeding.
What is the difference between deny and reject?
deny drops the packet silently, so the client waits for a timeout. reject sends an ICMP unreachable, so the client fails immediately. deny is marginally quieter to a scanner; reject is friendlier to legitimate clients that hit the wrong port.
How does ufw limit work?
It blocks a source address that has attempted six or more connections in the last thirty seconds. It applies per source, so it stops automated brute forcing without affecting normal use. It is available for IPv4 and IPv6 in current versions.
Does ufw handle IPv6?
Yes, if IPV6=yes is set in /etc/default/ufw, which is the default on current releases. Rules created without an explicit address apply to both families. A rule specifying an IPv4 source applies only to IPv4, so IPv6 needs its own.
How do I remove a rule?
Run ufw status numbered to list rules with their positions, then ufw delete followed by the number. You can also delete by repeating the original rule with delete in front of it, which is safer in a script because the numbering shifts as rules are removed.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Add the services you need to allow and copy the generated ufw commands in the right order.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.