Secure client portal

Networking

How to Open Ports on a Linux VPS (UFW, firewalld, iptables)

Open TCP/UDP ports on a Linux VPS with UFW, firewalld, or iptables. Verify with ss and an external port check.

On a Linux VPS, “opening a port” means allowing inbound traffic through the host firewall—and often a second firewall in the cloud control panel. It is not the same as port forwarding on a home router.

This guide covers UFW (Ubuntu/Debian), firewalld (AlmaLinux/Rocky/RHEL), and a short iptables/nft note, plus how to verify the service is actually listening.

Never lock yourself out of SSH. Keep port 22/tcp (or your SSH port) allowed from your IP before you enable a default-deny firewall.

What you need before changing firewall rules

  1. Root or a sudo-capable user.
  2. The port number and protocol (TCP, UDP, or both). Game servers often need both.
  3. Confirmation the application is bound to 0.0.0.0 or the public interface—not only 127.0.0.1.
  4. Access to your provider’s security group / network firewall UI if one exists (many VPS panels have a second layer).

Check whether the service is listening

sudo ss -tulpn | head -n 50
# or filter:
sudo ss -tulpn | grep -E ':(22|80|443|30120|25565)\s'
ColumnMeaning
LISTEN / UNCONNTCP listening vs UDP socket
Local Address0.0.0.0:30120 is public; 127.0.0.1:30120 is local-only
ProcessConfirms the expected binary owns the port

If nothing listens, opening the firewall will not help—fix the application first.

Ubuntu / Debian: UFW

Install and enable carefully:

sudo apt update
sudo apt install -y ufw
sudo ufw allow OpenSSH
# or: sudo ufw allow 22/tcp
sudo ufw enable
sudo ufw status verbose

Open a web stack:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Open a game port (example: FiveM 30120 TCP+UDP):

sudo ufw allow 30120/tcp
sudo ufw allow 30120/udp
sudo ufw reload
sudo ufw status numbered

Delete a mistaken rule:

sudo ufw status numbered
sudo ufw delete 3

AlmaLinux / Rocky / RHEL: firewalld

sudo systemctl enable --now firewalld
sudo firewall-cmd --state

Permanent rules (survive reboot):

sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-port=80/tcp
sudo firewall-cmd --permanent --add-port=443/tcp
sudo firewall-cmd --permanent --add-port=30120/tcp
sudo firewall-cmd --permanent --add-port=30120/udp
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

iptables / nftables (only if you are not using UFW or firewalld)

Do not mix raw iptables edits with UFW or firewalld. Pick one stack.

Example nftables snippet for SSH + HTTP/S (illustrative—adapt to your distro’s firewall service):

sudo nft list ruleset
# Prefer the distro firewall frontend unless you already manage nftables as policy.

If you inherit a host that already uses iptables-persistent, document every change and keep a console/VNC recovery path.

Cloud / provider security groups

Many providers add a network ACL in front of the VM:

  1. Open the VPS networking or firewall page.
  2. Allow the same TCP/UDP ports you opened on the OS.
  3. Restrict SSH to your IP when the UI supports source CIDR.

If OS firewall is open and ss shows a public listen address but an external port check fails, the provider firewall is the usual culprit.

Verify from outside

  1. From another network (phone LTE is fine), run an online TCP port check against your public IP.
  2. For UDP game ports, have a client attempt a direct connect; TCP checkers cannot fully prove UDP.
  3. On the VPS, watch hits while testing:
sudo tcpdump -ni any port 30120

Common ports cheat sheet

ServicePortNotes
SSH22/tcpRestrict by source IP when possible
HTTP / HTTPS80/443 tcpNeeded for web and most ACME HTTP-01 flows
FiveM30120 tcp+udpSee FiveM ports guide; txAdmin often 40120/tcp
Minecraft Java25565 tcpUDP only for specific proxies/query setups
MySQL/MariaDB3306/tcpKeep private

Safe defaults

  • Default deny inbound; allow only what you run.
  • Do not expose panel, database, Redis, or RDP-equivalent admin ports to 0.0.0.0/0 without a strong reason and IP allow lists.
  • After changes, re-check SSH before you disconnect.


Frequently Asked Questions

Do I still need port forwarding on a VPS?

Usually no. A VPS with a public IP needs firewall allow rules (and sometimes a cloud security group), not home-router NAT. See VPS Port Forwarding Explained.

UFW allowed the port but players still cannot connect. What next?

Confirm the game process is listening with ss -tulpn, check protocol (TCP vs UDP), and open the same port in any cloud/provider firewall panel.

Should I open MySQL 3306 to the world?

No. Keep databases on localhost or a private network. Use an SSH tunnel or restrict to specific IPs if remote access is required.


Need help?

If you are stuck after following this guide, open a ticket from the Chapter22 client area with the exact error, the port or DNS change you made, and whether the service listens locally (ss / Resource Monitor) but fails externally.

Build the server. Grow the community. Start your next chapter.

Need hosting that matches the workload?

Pick game hosting or web hosting.

Chapter22 sells managed game servers and web hosting. These VPS skill guides still apply if you operate your own VPS elsewhere.