How to Open Ports on a VPS: UFW, iptables & firewalld
A service on your VPS can be running perfectly and still be unreachable, because a firewall is dropping the traffic before it gets there. This guide shows you how to open a port with the three firewalls you'll meet on Linux servers (UFW, firewalld and plain iptables), how to make the rule survive a reboot, and how to test it from outside the server.
Quick answer: on Ubuntu or Debian run sudo ufw allow 443/tcp. On AlmaLinux, Rocky or RHEL run sudo firewall-cmd --permanent --add-port=443/tcp && sudo firewall-cmd --reload. Then check that your cloud provider's firewall (security group) allows the port as well.
Before you start: is anything listening on the port?
Opening a port only helps if a program is listening on it. Check first:
sudo ss -tulpn
Look for your port in the Local Address column:
0.0.0.0:443 or [::]:443 means the service accepts connections from anywhere. This is what you want for a public service.
127.0.0.1:3000 means it only listens on the server itself. No firewall rule will make it reachable; change the app's bind address, or put a reverse proxy such as Nginx in front of it.
- If the port isn't in the list at all, the service isn't running. Start it before you touch the firewall.
Keep your SSH session safe. Before enabling or reloading a firewall, make sure SSH (port 22, or your custom port) is allowed. Locking yourself out of a VPS usually means a trip to the provider's web console.
Open a port with UFW (Ubuntu and Debian)
UFW ("Uncomplicated Firewall") is the default front end on Ubuntu. Check its state:
sudo ufw status verbose
Allow SSH first, then the ports you need, then enable the firewall:
sudo ufw allow OpenSSH # or: sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
Useful variations:
sudo ufw allow 8000:8100/tcp # a port range
sudo ufw allow from 203.0.113.10 to any port 5432 # one IP only (e.g. a database)
sudo ufw status numbered # list rules with numbers
sudo ufw delete 3 # remove rule number 3
UFW rules are saved automatically and survive a reboot.
Open a port with firewalld (AlmaLinux, Rocky, RHEL, Fedora)
firewalld groups rules into zones. Most servers use the public zone. Check what's open:
sudo firewall-cmd --get-active-zones
sudo firewall-cmd --list-all
Open a port permanently, then reload so it takes effect:
sudo firewall-cmd --permanent --add-port=443/tcp
sudo firewall-cmd --reload
For well-known services you can use the service name instead of the number:
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reload
Without --permanent the rule only lasts until the next reload or reboot. That's handy for a quick test, but easy to forget.
Open a port with iptables
If your server has no UFW or firewalld, or you manage rules by hand, use iptables directly. List the current rules with line numbers:
sudo iptables -L INPUT -n --line-numbers
Rule order matters: iptables stops at the first match. If there's a REJECT or DROP rule near the end of the chain, your new rule must go above it. Insert it at a position rather than appending it:
sudo iptables -I INPUT 5 -p tcp --dport 443 -m state --state NEW -j ACCEPT
Replace 5 with the line number of the first REJECT/DROP rule. On a server without one, -A INPUT (append) is fine.
Make iptables rules survive a reboot
iptables rules live in memory and disappear on reboot unless you save them. On Ubuntu or Debian:
sudo apt install iptables-persistent
sudo netfilter-persistent save
This writes the rules to /etc/iptables/rules.v4 (and rules.v6 for IPv6), which are loaded at boot. Run sudo netfilter-persistent save again after every change.
Don't mix tools. UFW and firewalld both write iptables/nftables rules for you. If one of them is active, add rules through it, not with raw iptables, or your changes may be overwritten on the next reload.
Don't forget the cloud provider's firewall
Many providers put a second firewall in front of your server: security groups on AWS, firewall rules on Google Cloud, security lists on Oracle Cloud, and cloud firewalls on DigitalOcean and Hetzner. Traffic has to pass both that firewall and the one on the server. If the port is open on the server but still unreachable from outside, this is almost always the reason. Add an inbound rule for the port in the provider's control panel.
On Oracle Cloud you also need to deal with the iptables rules Oracle ships in its images. That's covered step by step in How to open ports 80 and 443 on an Oracle Cloud VPS.
Test the port from outside the server
Testing from the server itself proves nothing about the firewall, because local traffic usually bypasses it. Run these from your own computer or another server:
nc -zv your.server.ip 443
curl -I https://your.server.ip --insecure
How to read the result:
| Result | What it usually means |
| succeeded / open | The port is open and something is listening. |
| Connection refused | The firewall let the traffic through, but nothing is listening on that port (or it's bound to 127.0.0.1). |
| Times out | A firewall is dropping the traffic, either on the server or at the cloud provider. |
If the port is open but your website returns an error, the problem has moved from the firewall to the web server. See how to fix Nginx 403 Forbidden and Nginx 502 Bad Gateway.
Only open what you need
Every open port is something an attacker can probe. A typical web server needs only 22 (SSH), 80 and 443. Keep databases (3306, 5432, 27017) and admin panels closed to the internet, or limit them to your own IP with a rule like the UFW from … to any port example above.
Would you rather not manage a server at all? With RackUp's managed WordPress and cloud app hosting we look after the server side for you, firewall included. If you want full control, our Developer VPS plans give you root access to set your own rules with the commands above.
Frequently Asked Questions
How do I check which ports are open on my VPS?
On the server, sudo ss -tulpn lists the ports programs are listening on, and sudo ufw status or sudo firewall-cmd --list-all shows what the firewall allows. To see what's reachable from the internet, test from another machine with nc -zv your.server.ip PORT.
Why is my port still closed after I opened it in UFW?
Usually for one of three reasons: the cloud provider's firewall (security group) is still blocking it, the service is listening on 127.0.0.1 instead of 0.0.0.0, or the service isn't running. Check each one in that order.
Do iptables rules survive a reboot?
No, not by default. Save them with iptables-persistent (sudo netfilter-persistent save) on Debian/Ubuntu. UFW and firewalld rules added with --permanent are saved automatically.
Should I use UFW, firewalld or iptables?
Use whatever your distribution ships with: UFW on Ubuntu/Debian, firewalld on RHEL-based systems. Both are front ends that manage the underlying iptables/nftables rules for you. Use raw iptables only if neither is installed.
Is it safe to open port 22 to the whole internet?
It's common, but you should use SSH keys, disable password login, and consider tools like fail2ban. For extra protection, allow port 22 only from your own IP address.