On a Linux VPS, “opening a port” means allowing inbound traffic through the host firewall—and often a second firewall in the cloud control panel. It is not the same as port forwarding on a home router.
This guide covers UFW (Ubuntu/Debian), firewalld (AlmaLinux/Rocky/RHEL), and a short iptables/nft note, plus how to verify the service is actually listening.
Never lock yourself out of SSH. Keep port 22/tcp (or your SSH port) allowed from your IP before you enable a default-deny firewall.
What you need before changing firewall rules
- Root or a sudo-capable user.
- The port number and protocol (TCP, UDP, or both). Game servers often need both.
- Confirmation the application is bound to
0.0.0.0or the public interface—not only127.0.0.1. - Access to your provider’s security group / network firewall UI if one exists (many VPS panels have a second layer).
Check whether the service is listening
sudo ss -tulpn | head -n 50
# or filter:
sudo ss -tulpn | grep -E ':(22|80|443|30120|25565)\s'
| Column | Meaning |
|---|---|
LISTEN / UNCONN | TCP listening vs UDP socket |
| Local Address | 0.0.0.0:30120 is public; 127.0.0.1:30120 is local-only |
| Process | Confirms the expected binary owns the port |
If nothing listens, opening the firewall will not help—fix the application first.
Ubuntu / Debian: UFW
Install and enable carefully:
sudo apt update
sudo apt install -y ufw
sudo ufw allow OpenSSH
# or: sudo ufw allow 22/tcp
sudo ufw enable
sudo ufw status verbose
Open a web stack:
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
Open a game port (example: FiveM 30120 TCP+UDP):
sudo ufw allow 30120/tcp
sudo ufw allow 30120/udp
sudo ufw reload
sudo ufw status numbered
Delete a mistaken rule:
sudo ufw status numbered
sudo ufw delete 3
AlmaLinux / Rocky / RHEL: firewalld
sudo systemctl enable --now firewalld
sudo firewall-cmd --state
Permanent rules (survive reboot):
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-port=80/tcp
sudo firewall-cmd --permanent --add-port=443/tcp
sudo firewall-cmd --permanent --add-port=30120/tcp
sudo firewall-cmd --permanent --add-port=30120/udp
sudo firewall-cmd --reload
sudo firewall-cmd --list-all
iptables / nftables (only if you are not using UFW or firewalld)
Do not mix raw iptables edits with UFW or firewalld. Pick one stack.
Example nftables snippet for SSH + HTTP/S (illustrative—adapt to your distro’s firewall service):
sudo nft list ruleset
# Prefer the distro firewall frontend unless you already manage nftables as policy.
If you inherit a host that already uses iptables-persistent, document every change and keep a console/VNC recovery path.
Cloud / provider security groups
Many providers add a network ACL in front of the VM:
- Open the VPS networking or firewall page.
- Allow the same TCP/UDP ports you opened on the OS.
- Restrict SSH to your IP when the UI supports source CIDR.
If OS firewall is open and ss shows a public listen address but an external port check fails, the provider firewall is the usual culprit.
Verify from outside
- From another network (phone LTE is fine), run an online TCP port check against your public IP.
- For UDP game ports, have a client attempt a direct connect; TCP checkers cannot fully prove UDP.
- On the VPS, watch hits while testing:
sudo tcpdump -ni any port 30120
Common ports cheat sheet
| Service | Port | Notes |
|---|---|---|
| SSH | 22/tcp | Restrict by source IP when possible |
| HTTP / HTTPS | 80/443 tcp | Needed for web and most ACME HTTP-01 flows |
| FiveM | 30120 tcp+udp | See FiveM ports guide; txAdmin often 40120/tcp |
| Minecraft Java | 25565 tcp | UDP only for specific proxies/query setups |
| MySQL/MariaDB | 3306/tcp | Keep private |
Safe defaults
- Default deny inbound; allow only what you run.
- Do not expose panel, database, Redis, or RDP-equivalent admin ports to
0.0.0.0/0without a strong reason and IP allow lists. - After changes, re-check SSH before you disconnect.
Related guides
- VPS Port Forwarding Explained (Firewall vs Home Router)
- How to Open Ports on a Windows VPS (Firewall + netsh portproxy)
- FiveM Ports Explained: 30120 TCP/UDP and txAdmin
- How to SSH Into Your VPS (Windows, Mac, Linux)
Frequently Asked Questions
Do I still need port forwarding on a VPS?
Usually no. A VPS with a public IP needs firewall allow rules (and sometimes a cloud security group), not home-router NAT. See VPS Port Forwarding Explained.
UFW allowed the port but players still cannot connect. What next?
Confirm the game process is listening with ss -tulpn, check protocol (TCP vs UDP), and open the same port in any cloud/provider firewall panel.
Should I open MySQL 3306 to the world?
No. Keep databases on localhost or a private network. Use an SSH tunnel or restrict to specific IPs if remote access is required.
Need help?
If you are stuck after following this guide, open a ticket from the Chapter22 client area with the exact error, the port or DNS change you made, and whether the service listens locally (ss / Resource Monitor) but fails externally.
Build the server. Grow the community. Start your next chapter.
