MHOSTMHOST

How to Open a Port in Ubuntu: UFW and iptables

Opening a port in Ubuntu takes one command: sudo ufw allow 8080/tcp. But the service often stays unreachable afterward, because an "open port" really means three conditions at once:

  1. A program is listening on the port on a public interface. If nothing runs on the port, there's nothing to open.
  2. The server's firewall allows the port — UFW or iptables.
  3. Your host's firewall allows the port, if the control panel has one.

This guide covers all three: check the service, open the port in UFW or iptables, test it from outside and work out why an open port might still not respond. Commands are for Ubuntu 22.04, 24.04 and 26.04, and for Debian. The examples open port 8080; use your own.

Step 1. Check That the Service Is Listening

See which ports programs on the server are using:

sudo ss -tlnp

For UDP ports (VPNs, game servers), swap the t flag for u: sudo ss -ulnp.

Find your port in the Local Address column and look at the address in front of it:

  • 0.0.0.0:8080 or *:8080 — the program accepts outside connections. All that's left is opening the port in the firewall.
  • 127.0.0.1:8080 — the program listens on localhost only. It's unreachable from outside even with the port open in the firewall. You need to change the program's own settings or put Nginx in front of it.
  • The port isn't listed — the program isn't running or listens on another port. Start it first.

To find a single port quickly: sudo ss -tlnp | grep :8080.

Step 2. Open the Port in UFW

UFW is Ubuntu's standard firewall. First check whether it's on and which rules exist:

sudo ufw status verbose

If the command isn't found, install UFW: sudo apt install -y ufw.

If the status is inactive, the firewall is off and blocks nothing. Before enabling it, always allow SSH, or you'll lock yourself out of the server:

sudo ufw allow OpenSSH

sudo ufw enable

Open a single port. Specify the protocol: tcp for websites, APIs and databases, udp for VPNs and most games:

sudo ufw allow 8080/tcp

sudo ufw allow 51820/udp

Without a protocol (sudo ufw allow 8080), the port opens for both TCP and UDP. It's better to open only the one you need.

Open a port range:

sudo ufw allow 3000:3010/tcp

Open a port for one IP only. This is how to open databases, control panels and other internal ports:

sudo ufw allow from 203.0.113.10 to any port 5432 proto tcp

Open a known program's ports by name. Nginx, Apache and OpenSSH come with ready-made profiles. List them with sudo ufw app list. For example, ports 80 and 443 for a website:

sudo ufw allow 'Nginx Full'

Rules take effect immediately and persist across reboots. Check the result: sudo ufw status.

How to Close a Port and Delete a Rule

The easiest way is to delete the rule with the same command that created it, adding delete:

sudo ufw delete allow 8080/tcp

Or by number. Show the rules with numbers and delete the one you want:

sudo ufw status numbered

sudo ufw delete 3

Numbers shift after a deletion, so list the rules again before deleting the next one.

You usually don't need to deny a port explicitly: by default, UFW blocks all incoming connections that have no allow rule. You can confirm this with the line Default: deny (incoming) in the output of sudo ufw status verbose.

How to Open a Port with iptables

iptables is the low-level tool UFW itself runs on top of. It's used directly on servers without UFW or when you need complex rules.

Don't mix the two. If UFW is enabled, manage ports only through it: rules added to iptables by hand vanish after a reboot and muddy the picture.

View the current rules for incoming connections:

sudo iptables -L INPUT -n --line-numbers

Open a TCP port:

sudo iptables -I INPUT -p tcp --dport 8080 -j ACCEPT

The -I flag puts the rule at the top of the chain. This matters: iptables checks rules from top to bottom, and an allow rule appended after a blocking rule never fires.

Open a UDP port, or a port for one IP only:

sudo iptables -I INPUT -p udp --dport 51820 -j ACCEPT

sudo iptables -I INPUT -p tcp -s 203.0.113.10 --dport 5432 -j ACCEPT

To delete a rule, use the same command with -D instead of -I:

sudo iptables -D INPUT -p tcp --dport 8080 -j ACCEPT

Save the rules. iptables rules live in memory and disappear after a reboot. To restore them automatically:

sudo apt install -y iptables-persistent

sudo netfilter-persistent save

Repeat the second command after every rule change. On current Ubuntu versions, the iptables-persistent package conflicts with UFW: apt will offer to remove UFW during installation. So install it only if you've decided to work without UFW.

Step 3. Check the Port from Outside

Test from another computer, not from the server itself: from inside, the port is reachable regardless of the firewall.

On Linux and macOS:

nc -zv SERVER_IP 8080

On Windows, open PowerShell:

Test-NetConnection SERVER_IP -Port 8080

How to read the result:

  • succeeded or TcpTestSucceeded : True — the port is open and the program responds.
  • Connection refused — the firewall lets the request through, but nothing listens on the port. Go back to step 1.
  • A timeout with no response — the request is blocked on the way: there's no UFW rule, or the port is closed in your host's firewall.

UDP ports can't be tested reliably this way: the protocol doesn't confirm a connection. Test them with the application itself — a VPN client or the game.

Port Is Open but Doesn't Work: Possible Causes

  • The program listens on localhost only. The most common cause. In the output of sudo ss -tlnp, the port shows 127.0.0.1. Find a setting like bind, host or listen in the program's config and set it to 0.0.0.0. For web apps, it's safer to keep localhost and serve them through Nginx: how to set up Nginx as a reverse proxy.
  • The port is closed in your host's firewall. Many providers have a separate network firewall or security groups in the control panel. It works in front of the server, and UFW rules don't affect it. Open the port there too.
  • Wrong protocol. You opened TCP but the app needs UDP, or the other way round. WireGuard and most games use UDP.
  • Another program has taken the port. Your service couldn't start, and something else answers on the port. Check the process name in the last column of sudo ss -tlnp.
  • The service runs in Docker. Docker publishes ports bypassing UFW: a port can be reachable from the internet with no rule at all, and ufw deny won't close it. For details and the fix, see how to install Docker on Ubuntu.
  • Your provider blocks the port. Outgoing port 25 (sending email) is often closed by hosts to fight spam. It's opened on request through support.

Which Ports to Open and Which Not To

Every open port is an entry point for attacks. Bots scan the whole internet and find a newly opened port within hours.

  • Open to everyone only what has to be public: 80 and 443 for websites, a game server port, a VPN port.
  • Open to your own IPs only internal ports: SSH (22), control panels, monitoring.
  • Don't expose databases and caches: MySQL (3306), PostgreSQL (5432), Redis (6379), MongoDB (27017). An open Redis without a password is one of the most common ways servers get hacked. If you need remote access to a database, open the port for one IP or connect through an SSH tunnel.
  • Limit SSH password guessing. The command sudo ufw limit OpenSSH blocks an IP that connects too often.
  • Review the list once a month. Compare sudo ufw status with what actually runs on the server and delete rules for services that are gone.

For the other server hardening steps, see what to do right after buying a VPS.

Checklist

FAQ

How do I see open ports in Ubuntu? Ports programs are listening on: sudo ss -tlnp. Ports allowed in the firewall: sudo ufw status. A port is reachable from outside only if it's in both lists.

Which is better: UFW or iptables? For a typical VPS, UFW: simple commands, and rules save themselves. iptables is for complex setups: port forwarding, NAT, fine-grained filtering.

Do I need to reboot the server after opening a port? No. UFW and iptables rules take effect as soon as you run the command.

How do I redirect port 80 to my app's port? It's better done with Nginx than with the firewall: Nginx accepts requests on 80 and 443 and passes them to the app, adding HTTPS along the way.

I enabled UFW and lost SSH access. What now? Log in through the web console (VNC) in your hosting panel and run sudo ufw allow OpenSSH. The console works directly, without the network or firewall.