Security & Hardening · about 2 min · 5 steps
Firewall baseline
Blocks incoming connections except SSH and the ports you choose. Outgoing traffic is allowed.
Runs on
- Debian / Ubuntu: supported
- RHEL / Fedora: supported
- Alpine: supported — Needs the Alpine community repository.
What it changes on your server
- Installs ufw (Debian, Ubuntu, Alpine) or firewalld (RHEL, Fedora).
- Denies incoming connections by default.
- Allows SSH on the port you're connected to, plus the ports you list.
- Turns the firewall on and keeps it on after reboots.
What Shellbay asks you
Which other ports should stay open?
SSH stays open automatically. List the ports of services people reach from outside, such as 80 and 443 for a website. Leave this empty to allow SSH only. Add /udp for UDP ports; TCP is the default.
- Ports to allow (optional)
- Up to 20 ports, each optionally /tcp or /udp
Example:
80, 443, 51820/udp
Steps
- Refresh the package list
- Install the firewall
- Allow SSH and your ports
- Turn on the firewall
- Show the active rules
Shellbay checks the server before the first step, and stops at the first step that fails.
When it's done
- The firewall is on. Incoming connections are blocked except SSH and the ports you listed.
- Run this workflow again to change the allowed ports.