Skip to content
Shellbay

Security & Hardening · about 2 min · 5 steps

Firewall baseline

Blocks incoming connections except SSH and the ports you choose. Outgoing traffic is allowed.

Runs on

  • Debian / Ubuntu: supported
  • RHEL / Fedora: supported
  • Alpine: supported — Needs the Alpine community repository.

What it changes on your server

  • Installs ufw (Debian, Ubuntu, Alpine) or firewalld (RHEL, Fedora).
  • Denies incoming connections by default.
  • Allows SSH on the port you're connected to, plus the ports you list.
  • Turns the firewall on and keeps it on after reboots.

What Shellbay asks you

  1. Which other ports should stay open?

    SSH stays open automatically. List the ports of services people reach from outside, such as 80 and 443 for a website. Leave this empty to allow SSH only. Add /udp for UDP ports; TCP is the default.

    Ports to allow (optional)
    Up to 20 ports, each optionally /tcp or /udp

    Example: 80, 443, 51820/udp

Steps

  1. Refresh the package list
  2. Install the firewall
  3. Allow SSH and your ports
  4. Turn on the firewall
  5. Show the active rules

Shellbay checks the server before the first step, and stops at the first step that fails.

When it's done

  • The firewall is on. Incoming connections are blocked except SSH and the ports you listed.
  • Run this workflow again to change the allowed ports.