ufw enable Locked Me Out: Recovery and Proper Order

Symptom

After enabling the firewall, SSH dies mid-session.

Root cause

ufw enable applied a default-deny before the SSH allow rule existed.

Fix, in order

1. From console/panel: allow SSH first, then enableufw allow 22/tcp && ufw enable
2. If you still have a session: set default policy before anythingufw default deny incoming; ufw default allow outgoing; ufw allow 22/tcp
3. Cloud provider security groups: rule out double-firewalling# cloud SG must ALSO allow 22

Prevent it coming back

Allow SSH, verify with ufw status, then enable — always that order.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Managed cloud hosting

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog