↑ ↓ select, Enter open, Esc close

Block an IP address or subnet with ufw

Caution: This command changes the system. Understand what it does before you run it.

Adjust the values, the command updates live
root@server
ufw insert 1 deny from 203.0.113.0/24

Inserts a deny rule at position 1 so it is checked before all allow rules. ufw evaluates rules from top to bottom, so a plain ufw deny at the end would be overridden by an existing port rule. The rule survives reboots and is removed with ufw delete deny from <quelle>.

Note: insert 1 fails if no rule exists yet, in that case simply use ufw deny from <quelle>. IPv6 addresses are sorted in separately before the first IPv6 rules.

Also searched as

  • ufw block ip address
  • ufw deny from subnet
  • ufw insert deny rule first

Related one-liners

All in Firewall

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.