Running a local firewall is almost always a good practice. Even when you are behind a network firewall, a local firewall protects you from threats on the inside of your network.
UFW stands for Uncomplicated FireWall, and is a program for managing a netfilter firewall. It provides a command line interface and aims to be uncomplicated and easy to use. UFW is far simpler than iptables and a good place to start unless you have very specialized needs.
You can install the
ufw package using you favorite package manager or the command:
pamac install ufw
Once UFW is installed you need to start and enable it using the commands:
sudo systemctl enable ufw.service sudo ufw enable
To view the current configuration you can use the command
ufw status. Here is what it looks like in a new install:
sudo ufw status verbose Status: active Logging: on (low) Default: deny (incoming), allow (outgoing), disabled (routed) New profiles: skip
This indicates that it will block all incoming traffic and allow all outgoing traffic. This is a good starting point for most desktop systems. However, often we will want to allow some incoming traffic. This can be done with the command
ufw allow. For example, if we want to allow incoming ssh traffic so we can connect to the machine from other machines on the network we could use the command:
sudo ufw allow ssh
If we wanted to also tcp connections to a local webserver on a non-standard https port, 8443. We could use the command:
sudo ufw allow in 8443/tcp
UFW and Applications
You may notice a difference in the above two commands. When we built the rules for ssh we used the name and for https we used the port number, 8443. This is because UFW has a small database of applications it knows the ports for. You can see the list with the command:
sudo ufw app list
For applications on the list you can add them by name. If you want to review the configuration for one of the applications, you can use the command
ufw app info. For example, to the configuration for ssh:
sudo ufw app info SSH Profile: SSH Title: SSH server Description: SSH server Port: 22/tcp
Some additional preconfigured applications can be added by installing the package
ufw-extras with your favorite package manager or the command:
pamac install ufw-extras
Rules can be removed with the
ufw delete command. For example, to delete our 8443 rules we could use the command:
sudo ufw delete allow 8443/tcp
You can also delete them by number. This is easier if you have a numbered list which you can see with the command:
sudo ufw status numbered Status: active To Action From -- ------ ---- [ 1] 22 ALLOW IN Anywhere [ 2] 22 (v6) ALLOW IN Anywhere (v6)
Now if we wanted to stop allowing ssh on ipv6 we could use the command:
sudo ufw delete 2
Prefer to use GUI applications and still want to manage your firewall? No problem. GUFW is a GTK front-end for UFW that aims to make managing a Linux firewall as accessible and easy as possible. It features pre-sets for common ports and p2p applications.
If it is not installed already gufw can be installed from the repos:
pamac install gufw
It will now be available in the menu as Firewall Configuration or by running
iptables is included as part of the Linux kernel. iptables is significantly more complicated than using a tool like UFW. As a result, a full tutorial on iptables is beyond the scope of this wiki. Using iptables on Manjaro should be the same for every distribution of Linux so there is plenty of available documentation. Some of this is linked below. Here are some basics to get you started.
To enable loading rules on startup you can use the command:
sudo systemctl enable iptables.service
This will load the rules from the file
To display the currently loaded rules:
sudo iptables -L
To save the current rules to a file
sudo sh -c "iptables-save > /etc/iptables/iptables.rules"
To load the rules from a file
sudo sh -c "iptables-restore > /etc/iptables/iptables.rules"
To allow ssh connections
sudo iptables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT sudo iptables -A OUTPUT -p tcp --sport 22 -m conntrack --ctstate ESTABLISHED -j ACCEPT