Firewall Rules for a WireGuard VPN
WireGuard's UDP port open; everything else reachable only through the tunnel. The services are already ticked: add your own addresses and pick your firewall.
- Free
- No Sign-Up
- Runs in Your Browser
Services to Open
Check Before You Apply
SSH is open to the whole internet. Limit it to your own addresses if they are fixed.
These rules replace the existing input rules. Check nothing else (Docker, fail2ban, the Proxmox firewall) manages this server's firewall first.
/etc/nftables.conf
#!/usr/sbin/nft -f
# /etc/nftables.conf: generated at frabs.net/tools/firewall-rule-generator/
flush ruleset
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
ct state established,related accept
ct state invalid drop
iif "lo" accept
ip protocol icmp icmp type { echo-request, destination-unreachable, time-exceeded } limit rate 10/second accept
ip6 nexthdr icmpv6 accept # IPv6 needs ICMPv6 for neighbour discovery
tcp dport 22 accept # SSH
udp dport 51820 accept # WireGuard
}
chain forward {
type filter hook forward priority 0; policy accept;
}
chain output {
type filter hook output priority 0; policy accept;
}
}
# Apply: nft -f /etc/nftables.conf
# Keep at boot: systemctl enable nftablesFirewall Rule Generator
WireGuard VPN firewall
WireGuard's UDP port open; everything else reachable only through the tunnel.
Apply the rules from a session you can recover: a provider console, or with a scheduled rollback, so a mistake cannot lock you out.
Server Types
Questions
Which ports should a wireguard vpn open?
Free Tools
More tools
Firewalls stop traffic coming in
Frabs stops the abuse going out: spam, scans and floods from any VM, caught by behaviour, not by port.