|
| 1 | +# TAGLINE |
| 2 | + |
| 3 | +Block traffic through Uncomplicated Firewall |
| 4 | + |
| 5 | +# TLDR |
| 6 | + |
| 7 | +**Deny** all traffic on a port |
| 8 | + |
| 9 | +```sudo ufw deny [port]``` |
| 10 | + |
| 11 | +Deny traffic for a **protocol** on a port |
| 12 | + |
| 13 | +```sudo ufw deny [port]/[protocol]``` |
| 14 | + |
| 15 | +Deny all traffic **from** a source address |
| 16 | + |
| 17 | +```sudo ufw deny from [source_address]``` |
| 18 | + |
| 19 | +Deny all traffic from a **subnet** |
| 20 | + |
| 21 | +```sudo ufw deny from 192.168.13.0/24``` |
| 22 | + |
| 23 | +Deny **UDP** from one host to another on a port |
| 24 | + |
| 25 | +```sudo ufw deny from 192.168.1.12 to 192.168.1.100 port 8080 proto udp``` |
| 26 | + |
| 27 | +Deny with a **comment** for documentation |
| 28 | + |
| 29 | +```sudo ufw deny in 23/tcp comment "block telnet"``` |
| 30 | + |
| 31 | +Deny **incoming** traffic on an interface by protocol |
| 32 | + |
| 33 | +```sudo ufw deny in on eth0 to 192.168.1.100 proto igmp``` |
| 34 | + |
| 35 | +**Simulate** a deny rule without applying it |
| 36 | + |
| 37 | +```sudo ufw --dry-run deny 80/tcp``` |
| 38 | + |
| 39 | +# SYNOPSIS |
| 40 | + |
| 41 | +**ufw** [_--dry-run_] **deny** [_rule_] |
| 42 | + |
| 43 | +# PARAMETERS |
| 44 | + |
| 45 | +**deny** |
| 46 | +> Drop matching traffic (inserts a deny/DROP rule) |
| 47 | +
|
| 48 | +_port_[**/**_protocol_] |
| 49 | +> Simple form: port number, optional **/tcp** or **/udp** |
| 50 | +
|
| 51 | +**from** _address_ |
| 52 | +> Match source address or network (CIDR) |
| 53 | +
|
| 54 | +**to** _address_ |
| 55 | +> Match destination address |
| 56 | +
|
| 57 | +**port** _port_ |
| 58 | +> Destination port (or range) when using full rule syntax |
| 59 | +
|
| 60 | +**proto** _protocol_ |
| 61 | +> Protocol: **tcp**, **udp**, **igmp**, **gre**, etc. |
| 62 | +
|
| 63 | +**in** / **out** |
| 64 | +> Direction of traffic |
| 65 | +
|
| 66 | +**on** _interface_ |
| 67 | +> Limit rule to a network interface |
| 68 | +
|
| 69 | +**comment** '_text_' |
| 70 | +> Attach a human-readable comment to the rule |
| 71 | +
|
| 72 | +**--dry-run** |
| 73 | +> Show what would change without applying it |
| 74 | +
|
| 75 | +# DESCRIPTION |
| 76 | + |
| 77 | +**ufw deny** adds a deny rule to Uncomplicated Firewall so matching packets are dropped (similar to iptables DROP). Rules can be simple port denials (`ufw deny 23/tcp`), source or network blocks (`ufw deny from 203.0.113.0/24`), or full five-tuple style rules with source, destination, port, protocol, and interface. |
| 78 | + |
| 79 | +Deny rules are useful for blocking known bad hosts, unused services, or entire subnets while keeping a default allow policy elsewhere. Prefer **deny** when you want silent drops; use **reject** (via `ufw reject`) when you want the peer to receive an explicit refusal. Use `ufw status numbered` to list rules and `ufw delete` to remove them by number. |
| 80 | + |
| 81 | +# CAVEATS |
| 82 | + |
| 83 | +Requires root or sudo. Rule order matters when combined with allows — more specific rules should be ordered carefully (`ufw insert`). A deny rule does not override a more specific earlier allow if packet matching selects the allow first. Application profile names must match installed profiles under `/etc/ufw/applications.d/`. Blocking yourself from SSH while managing a remote host can lock you out; prefer `--dry-run` and ensure alternate access first. |
| 84 | + |
| 85 | +# HISTORY |
| 86 | + |
| 87 | +Part of **ufw** (Uncomplicated Firewall), the Ubuntu-originated frontend for iptables/nftables. |
| 88 | + |
| 89 | +# INSTALL |
| 90 | + |
| 91 | +```dnf: sudo dnf install ufw``` |
| 92 | + |
| 93 | +```pacman: sudo pacman -S ufw``` |
| 94 | + |
| 95 | +```apk: sudo apk add ufw``` |
| 96 | + |
| 97 | +```zypper: sudo zypper install ufw``` |
| 98 | + |
| 99 | +<!-- packages: 2026-08-02 --> |
| 100 | + |
| 101 | +# SEE ALSO |
| 102 | + |
| 103 | +[ufw](/man/ufw)(8), [ufw-allow](/man/ufw-allow)(8), [ufw-enable](/man/ufw-enable)(8), [ufw-disable](/man/ufw-disable)(8), [iptables](/man/iptables)(8), [nftables](/man/nftables)(8) |
| 104 | + |
| 105 | +# RESOURCES |
| 106 | + |
| 107 | +```[Source code](https://git.launchpad.net/ufw)``` |
| 108 | + |
| 109 | +```[Documentation](https://help.ubuntu.com/community/UFW)``` |
| 110 | + |
| 111 | +<!-- verified: 2026-08-02 --> |
0 commit comments