Firewall

Open what the server serves. Close the panel to the world.

UFW on Ubuntu and Debian. firewalld on AlmaLinux and Rocky. SSH stays allowed until a second session proves it. Mail ports stay open if mail is on the box.

The list

22, 80, 443, and only the rest that you use

Web

80 and 443. Port 80 stays if Let’s Encrypt uses HTTP-01. Closing it because “we are on HTTPS” is how renewal fails.

Panel

Hestia, DirectAdmin and cPanel ports restricted to your IP, or left and covered by Fail2Ban if your IP changes. Not both forgotten.

Mail and databases

25, 465, 587, 993 if mail is local. 3306 and 6379 are not public. A database that only the same server uses does not need a hole.

Provider firewall

Hetzner and OVHcloud have a second wall, outside the VPS

A port open in UFW and closed in the cloud firewall still fails. We check both. The console is the rollback if SSH is the port we got wrong.

SSH security → · Fail2Ban →

Price

€55 an hour. Usually with the SSH change, not instead of it.

Minimum 1 hour. A firewall with no key login yet is an incomplete job. We do not enable a default-deny until the console is confirmed.

Pricing →

Panel port open, or no firewall at all?

Tell us the distribution and whether mail runs on the server. No root password in the first message.

Request Support → Contact Us