↑ ↓ select, Enter open, Esc close

Allow a port only from a specific IP with ufw

Caution: This command changes the system. Understand what it does before you run it.

Adjust the values, the command updates live
root@server
ufw allow from 198.51.100.0/24 to any port 22 proto tcp

Allows incoming TCP connections on the port only from the given address or subnet in CIDR notation. Other sources fall back to the default policy. Typical for admin access such as SSH, database ports or the Plesk panel on port 8443.

Note: An existing general rule for the same port (ufw allow 22/tcp) must be removed afterwards, otherwise the port stays open for everyone.

Also searched as

  • ufw allow ssh from specific ip
  • restrict port to ip address ufw
  • ufw allow from subnet to port

Related one-liners

All in Firewall

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.