UFW on CloudSonic

Block all unwanted inbound traffic at the firewall level from the moment your server is provisioned

TL;DR UFW

UFW is configured on every CloudSonic server allowing only ports 80, 443, and 2222, with all other inbound traffic blocked at the firewall level from day one.

UFW is a user-friendly frontend for iptables that manages firewall rules on every CloudSonic server, configured from provisioning to allow only ports 80, 443, and 2222 with all other inbound traffic blocked. CrowdSec and Fail2ban write dynamic block rules directly to iptables as threats are detected, while all monitoring ports for Prometheus exporters are bound to the Tailscale interface and never exposed through UFW. UFW sits alongside AppArmor, CrowdSec, and Fail2ban as one of four independent security layers active on every CloudSonic server.

UFW for Firewall Management on CloudSonic

UFW on CloudSonic is configured during provisioning to allow only ports 80, 443, and 2222 with all other inbound traffic blocked by default. CrowdSec and Fail2ban write dynamic block rules directly to iptables as threats are detected, working independently of UFW's static rules so malicious IP addresses are banned in real time without requiring UFW rule changes. All monitoring ports for Prometheus exporters are bound to the Tailscale interface rather than the public interface, so they are never exposed through UFW regardless of firewall configuration.

Warning Modifying UFW rules incorrectly can lock you out of your server; always ensure your Tailscale connection is active and test rules carefully before removing any existing allow rules.

Useful Commands

sudo ufw status verbose