Labthrift LabthriftWhat to buy. What to skip. Why.

Written 25 Aug 2026. This is a how-to, not a product card.

Turn on a simple firewall without locking yourself out

After SSH from the couch works, allow OpenSSH, then turn on ufw. The computer stays reachable. Surprise inbound ports don't.

This is a small safety step for a computer that is already working. Allow the door you use first. Then turn on the guard. Prefer see which doors the computer left open first so you know what is already listening.

Skip until SSH works

If you cannot log in with SSH from the couch, stop. Fix that first. Password SSH should already work. A key is optional, but logging in with a key is a nice next step once the password login is boring.

What ufw is

ufw is a simple on/off firewall on Debian and Ubuntu. It blocks surprise inbound ports that you did not mean to leave open. It is software on the computer, not a new appliance, and it is not pfSense. SSH must be allowed before you turn it on or you can lock yourself out.

Allow SSH first

While you are logged into the computer, run:

sudo ufw allow OpenSSH

This makes an exception for SSH before the firewall starts blocking inbound connections. If the OpenSSH profile is not available, sudo ufw allow 22/tcp is the direct version. The order matters. Allow first, enable second.

Turn it on

Now enable ufw:

sudo ufw enable

It warns that existing SSH connections may be disrupted. Because OpenSSH is already allowed, type yes and press Enter. Then check:

sudo ufw status

You should see Status: active and an OpenSSH rule marked ALLOW. Keep the current SSH window open while you test a second login from the laptop.

On a computer that only does SSH, OpenSSH is the whole rule list. If it already serves files or answers DNS, the two sections below add those services back.

If you lock yourself out

Plug a screen and keyboard into the computer, log in at the console, and run sudo ufw disable. Then fix the SSH rule and try again. Don't solve this by opening port 22 on the router. SSH stays inside the house, as explained in keep the computer on the house network.

If you already have a file share

Turning on the firewall can make a working file share disappear from Finder or File Explorer. Nothing broke. Samba was simply never told it was welcome. While you are logged into the computer, run:

sudo ufw allow Samba

Samba is a profile that ships with Debian and Ubuntu, so one word covers the ports the share needs. If you see the profile is unknown, sudo ufw app list prints the profile names it actually has. Then re-check the rules:

sudo ufw status

You should now see Samba marked ALLOW next to OpenSSH. Open the share again from the laptop or the phone and it should be back. If the share vanished after ufw and allowing Samba did not bring it back, when the house share disappeared, check the computer. If the share is there but the password fails, that is set or change the house-share password. This rule is for the house network only. Don't open SMB to the internet and don't forward its ports on the router, the same boundary as keep the computer on the house network.

If you already run Pi-hole

Same story for the house ad block. Pi-hole answers name lookups for every phone and laptop, so the firewall has to let DNS in. If it does not, names stop resolving and the whole house looks like the internet is down. Allow DNS on the computer:

sudo ufw allow 53/tcp

sudo ufw allow 53/udp

DNS uses both, so allow both. Ubuntu does not ship a Pi-hole ufw profile, so the two port lines are the honest path. Then re-check:

sudo ufw status

You should see 53/tcp and 53/udp marked ALLOW next to OpenSSH. Load a couple of sites from a phone. Names should still resolve and ads should still drop. House network only. Don't forward port 53 on the router.

Nothing on the router changes here. Router DNS still points at the computer, exactly as in point the house at the ad block. You are only letting the house reach a service that was already running.

What next

Once a week, keep the computer updated. That is enough for now. Don't buy a firewall appliance for this job.

Skip

Sources

Ubuntu Server: firewalls. Debian: ufw manual. Official pages only. For a working login, see SSH from the couch. For the house-network boundary, see keep the computer on the house network. For the share these rules protect, see a file share on the computer. For the ad block, see the first useful thing on the computer.

Also on this topic

Slow down password guesses on SSHAfter the firewall is on and key login is boring, you can let the computer briefly refuse an address that keeps guessing the password. Skip this on day one. Don't forward port 22. Turn off password login once the key worksAfter the laptop key login is boring, tell SSH to stop accepting the password. The key is how you get in. A keyboard on the computer is the backup now. Log in with a key, not the password every timeAfter password SSH works for a while, put a key on your laptop so the computer trusts that laptop. Keep the password as a backup at first. SSH from the couchType commands on the computer from your laptop, on the house network. Password login first. Don't open this to the internet. Keep the computer on the house networkSSH and Pi-hole belong on the house network. Skip this if you never opened the router settings. Don't forward port 22. Keep the computer updatedOnce a week, give the computer its fixes so SSH and Pi-hole are not sitting on last year's bugs. Let the computer apply weekly fixes without youAfter the weekly two-command habit is boring, you can let the computer apply those same fixes by itself. Skip this until that habit is boring. Don't let it reboot on its own.