This document describes the firewall configuration implemented using UFW (Uncomplicated Firewall) on a Linux server.
sudo ufw default deny incoming
sudo ufw default allow outgoing
| Direction | Policy |
|---|---|
| Incoming | Denied |
| Outgoing | Allowed |
This follows the principle of least privilege.
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
| Port | Protocol | Purpose |
|---|---|---|
| 80 | TCP | HTTP |
| 443 | TCP | HTTPS |
These ports are exposed to the public internet.
sudo ufw allow 51820/udp
| Port | Protocol | Purpose |
|---|---|---|
| 51820 | UDP | WireGuard VPN |
The server listens for encrypted VPN connections on UDP port 51820.
wg010.44.0.0/24| Device | User | VPN IP | Role |
|---|---|---|---|
| Laptop | Michael | 10.44.0.2 | Remote Access |
| Laptop | Erin | 10.44.0.3 | Remote Access |
| Laptop | Mouhamed | 10.44.0.4 | Remote Access |
Only authenticated peers can access internal services.
sudo ufw allow in on wg0 from 10.44.0.2 to any port 22 proto tcp
sudo ufw allow in on wg0 from 10.44.0.3 to any port 22 proto tcp
sudo ufw allow in on wg0 from 10.44.0.4 to any port 22 proto tcp
| Port | Protocol | Access Scope |
|---|---|---|
| 22 | TCP | VPN only |
SSH is not publicly accessible
Users must:
10.44.0.x addressThis prevents:
sudo ufw allow 5432/tcp
Enable UFW with:
sudo ufw enable
Check active rules:
sudo ufw status numbered