# cockpit-ufw-module: Uncomplicated Firewall in Cockpit

LLMS index: [llms.txt](/en/llms.txt)

---

UFW on a home or small server is usually configured over SSH: `ufw status numbered`, then `ufw allow 443/tcp`. [cockpit-ufw-module](https://gitlab.com/cockpit-modules/cockpit-ufw-module) covers the same cycle in the browser: package, status, policies, rules. It is one panel from the [cockpit-modules](/en/posts/cockpit-modules/) group — **UFW** under **Tools**.

The UI is Russian, in PatternFly v5. You need Cockpit **264+** and administrator rights for writes. MIT license; current release is tag `v.1.0.1`.

## Why a panel if `ufw` already exists

The client is already there: system `ufw`. What is missing is a view without a terminal and safe input: port, CIDR, rule number.

The panel does not replace iptables with its own engine. HTML and JS call host commands through `cockpit.spawn` as argv arrays, not shell strings. Input is validated on the client: port (including a range and a list), IPv4/IPv6 and CIDR, action `allow` / `deny` / `reject` / `limit`. Without Cockpit admin rights, package and rule operations do not run.

## What the page shows

Four blocks, top to bottom:

| Block | Job |
|-------|-----|
| ufw package | installed or not, version, manager (APT, DNF, YUM, Pacman), install and remove |
| Status | active / inactive, logging level, incoming/outgoing policies, enable / disable / reload |
| Rules | table from `ufw status numbered`: number, to, action, from, delete |
| Add rule | action, protocol, port, source IP/CIDR |

While the firewall is off, the rules table is hidden: UFW does not apply them, even if the config still has entries. The counter then reads “N rules (inactive)”.

## Installing the module

Use the [store](https://gitlab.com/cockpit-modules/cockpit-modules-store) if it is already on the host. Otherwise install by hand:

```bash
git clone https://gitlab.com/cockpit-modules/cockpit-ufw-module.git
cd cockpit-ufw-module
sudo ./install.sh
```

Files go to `/usr/share/cockpit/ufw`. Refresh Cockpit — **UFW** appears under **Tools**.

For the current user without root:

```bash
./install.sh --user
```

The module lands in `~/.local/share/cockpit/ufw`.

> [!NOTE]
> `install.sh` installs only the panel. The `ufw` package is installed from the UI, with **Install ufw**.

## Typical flow on a clean host

Order matters more than the buttons. After the package install the module runs `ufw --force reset`, sets **allow** for incoming and outgoing, opens `22/tcp`, and enables the `ufw` systemd unit. It does **not** enable the firewall — that is a separate button with an SSH warning.

1. **Tools → UFW → Install ufw.** Confirm. On APT this starts with `apt-get update`.
2. Add explicit rules for what you manage from this host. Cockpit listens on **9090/tcp** — after the package install that rule is missing, only SSH 22 is present. If you later set incoming to `deny` without 9090, the panel disappears.
3. Services you need: `80/tcp`, `443/tcp`, a range such as `8000:8010`. The source can be a CIDR, for example `10.0.0.0/8`.
4. Before adding, the UI shows a command preview (`ufw allow 443/tcp`) — the same argv that will run on the host.
5. **Enable.** While default incoming is `allow`, access is not cut: only explicit deny/reject/limit rules take effect.
6. Once SSH, Cockpit, and sites still work — switch the incoming policy to `deny`. Leave outgoing on `allow` in the usual case.

Examples the form accepts:

```
22/tcp
443,80
8000:8010
from 10.0.0.0/8 to any port 443 proto tcp
```

`limit` is UFW’s rate limit on new connections, useful on 22. `reject` replies with ICMP/TCP reset; `deny` drops silently.

> [!WARNING]
> **Install ufw** runs `ufw --force reset`. Existing rules on the host are wiped. On a host that already has a tuned firewall, install the package by hand and use the panel only for status and small edits.

## What the panel does not do

This is not the full `ufw` from the man page. The UI has no:

- application profiles (`ufw allow OpenSSH`, `ufw app list`);
- interface binding (`on eth0`);
- rule comments;
- in/out direction on the add form — new rules are inbound;
- logging level changes (the **Logging** line is read-only);
- routed policy, even though `ufw status verbose` is parsed.

Removing the package disables UFW (`ufw --force disable`) and uninstalls it through the system manager; APT uses `--purge`.

Local check without touching a live host — Docker Compose from the repository: a privileged container with systemd, Ubuntu, Cockpit, and ufw, default `http://localhost:9090`, login `admin` / `admin`. That is a demo, not a production pattern.

Sources, issues, and tags live at [gitlab.com/cockpit-modules/cockpit-ufw-module](https://gitlab.com/cockpit-modules/cockpit-ufw-module). Neighbouring panels in the same group: fail2ban, cron, CertManager.

---

Backlinks:

- [cockpit-modules: web panels for day-to-day operations](/en/posts/cockpit-modules/)
