Firewall: Ports and Addresses
Decide who can reach your server
Decide who can reach your server
The Firewall page controls the server's UFW firewall: turn it on or off, see every rule, open a port, allow or block an address. The rules are yours: Opensolr keeps only its own access to the server.
Where: Servers › My Servers › your server › System › Firewall
01 · Firewall on or off
UFW Firewall Status shows whether the firewall is on.
- Enable Firewall turns it on. Make sure SSH (port 22) is allowed first, or you lock yourself out of SSH.
- Disable Firewall opens every port to the internet. You confirm twice. Use it only to debug, for a short time.
- Refresh Status reads the state again.
02 · Add a rule
- Click + Add Rule.
- Action: Allow or Block/Deny.
- Type: Port, from any source; IP / range, all ports; or IP / range + port.
- Fill Port and/or IP Address or Range: one address, or a range such as
192.168.1.0/24. - Protocol: TCP, UDP or Both TCP & UDP. Add a Comment so you remember why the rule is there.
- Click Add Rule.
03 · The rule list
- One row can stand for several firewall rules: both directions, both protocols, IPv4 and IPv6. Delete removes all of them, after you confirm.
- Rows marked Protected are Opensolr's own access to the server. They have no Delete button.
- Filter by text (port, IP, comment), by IN / OUT, ALLOW / DENY, IPv4 / IPv6, or Protected / Custom. The count next to the filters shows how many rows match.
- Refresh Rules reads the list again.
Turning on WireGuard opens its port only for the servers you link.
System menu
- System menu
- SSH keys
- Firewall
- Logs
- Config
- Alerts
- Housekeeping