Firewall: Ports and Addresses

Decide who can reach your server

Decide who can reach your server

The Firewall page controls the server's UFW firewall: turn it on or off, see every rule, open a port, allow or block an address. The rules are yours: Opensolr keeps only its own access to the server.

Where: Servers › My Servers › your server › System › Firewall

01 · Firewall on or off

UFW Firewall Status shows whether the firewall is on.

  • Enable Firewall turns it on. Make sure SSH (port 22) is allowed first, or you lock yourself out of SSH.
  • Disable Firewall opens every port to the internet. You confirm twice. Use it only to debug, for a short time.
  • Refresh Status reads the state again.

02 · Add a rule

  1. Click + Add Rule.
  2. Action: Allow or Block/Deny.
  3. Type: Port, from any source; IP / range, all ports; or IP / range + port.
  4. Fill Port and/or IP Address or Range: one address, or a range such as 192.168.1.0/24.
  5. Protocol: TCP, UDP or Both TCP & UDP. Add a Comment so you remember why the rule is there.
  6. Click Add Rule.

03 · The rule list

  • One row can stand for several firewall rules: both directions, both protocols, IPv4 and IPv6. Delete removes all of them, after you confirm.
  • Rows marked Protected are Opensolr's own access to the server. They have no Delete button.
  • Filter by text (port, IP, comment), by IN / OUT, ALLOW / DENY, IPv4 / IPv6, or Protected / Custom. The count next to the filters shows how many rows match.
  • Refresh Rules reads the list again.

Turning on WireGuard opens its port only for the servers you link.

System menu