Open what the server serves. Close the panel to the world.
UFW on Ubuntu and Debian. firewalld on AlmaLinux and Rocky. SSH stays allowed until a second session proves it. Mail ports stay open if mail is on the box.
22, 80, 443, and only the rest that you use
80 and 443. Port 80 stays if Let’s Encrypt uses HTTP-01. Closing it because “we are on HTTPS” is how renewal fails.
Hestia, DirectAdmin and cPanel ports restricted to your IP, or left and covered by Fail2Ban if your IP changes. Not both forgotten.
25, 465, 587, 993 if mail is local. 3306 and 6379 are not public. A database that only the same server uses does not need a hole.
Hetzner and OVHcloud have a second wall, outside the VPS
A port open in UFW and closed in the cloud firewall still fails. We check both. The console is the rollback if SSH is the port we got wrong.
€55 an hour. Usually with the SSH change, not instead of it.
Minimum 1 hour. A firewall with no key login yet is an incomplete job. We do not enable a default-deny until the console is confirmed.
Panel port open, or no firewall at all?
Tell us the distribution and whether mail runs on the server. No root password in the first message.
