Free tools Windows power users keep installed
One-click scans. No signup required.
To allow SSH through UFW, add an inbound TCP rule for port 22, then enable UFW if it is not already active: sudo ufw allow 22/tcp followed by sudo ufw enable. Check the result with sudo ufw status verbose. If you are connected remotely, keep your current SSH session open while changing firewall rules.
Before opening port 22
UFW is Ubuntu’s default firewall configuration tool, and Debian’s UFW manual documents the same rule-management commands. Before changing the firewall, confirm that the SSH daemon is running and configured to listen on TCP port 22. A firewall rule cannot make a stopped service or a daemon listening on a different port reachable.
If you are administering the machine over SSH, leave the existing session open until you have confirmed a new connection works. That gives you a way to correct a rule without losing your current access.
Allow SSH through UFW
-
Add the rule:
sudo ufw allow 22/tcp. The explicit numeric form makes clear that the rule is for TCP port 22.PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
-
If UFW is not enabled, enable it:
sudo ufw enable. Add the SSH allowance first so enabling the firewall does not block the expected SSH traffic. -
Review the active rules:
sudo ufw status verbose. For a concise check, usesudo ufw status. -
From another terminal or machine, try a new SSH connection before closing the session you already have open.
Ubuntu also documents sudo ufw allow 22. You can use the service-name form sudo ufw allow ssh as well; UFW can resolve service names using entries in /etc/services. The numeric 22/tcp form is the most explicit choice when the intent is specifically SSH over TCP port 22. Ubuntu’s UFW documentation covers the rule, enabling the firewall, and checking its status.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Limit SSH access to a trusted source
An unrestricted allow rule makes SSH reachable through the host firewall from any source that can reach the machine. If only a management host or network needs access, restrict the rule to that source instead:
sudo ufw allow proto tcp from 192.168.0.2 to any port 22
Replace 192.168.0.2 with the trusted host’s address. For a subnet, Ubuntu documents a form such as 192.168.0.0/24. Use an address or subnet that matches the actual source address UFW sees; an incorrect restriction can prevent legitimate connections. See Ubuntu’s UFW guidance for source-restricted rules.
Allow versus rate-limit SSH
A standard allow rule permits matching SSH connections without UFW’s per-rule connection-rate limit. Debian’s UFW manual also documents ufw limit ssh/tcp, which applies a rate limit to matching connections. A numeric alternative is sudo ufw limit 22/tcp. Choose the rule that fits your access policy; rate limiting is not a substitute for keeping the SSH service and network configuration secure. The Debian UFW manual also describes per-rule logging options such as log and log-all.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesPreview, inspect, or remove a rule
-
Preview a change:
sudo ufw --dry-run allow 22/tcpshows the proposed operation without applying it. -
List rules with numbers:
sudo ufw status numbereddisplays numbered entries, which can help identify the exact rule to remove. -
Delete by rule:
sudo ufw delete allow 22/tcpremoves the matching allow rule. -
Delete by number: use the number shown by
sudo ufw status numberedwith UFW’s numbered-rule deletion command. Check the list again before deleting, because rule numbers can change after a deletion.What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Enable logging:
sudo ufw logging onturns on UFW logging; Ubuntu’s UFW wiki shows this alongside enabling and checking the firewall.
For command details, consult the Ubuntu UFW documentation, the Debian UFW manual, and the Ubuntu UncomplicatedFirewall wiki.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If port 22 still cannot be reached
A UFW status line showing SSH or 22/tcp as allowed confirms the local firewall rule, not end-to-end reachability. Check the following in order:
-
Confirm the listener: verify that the SSH daemon is running and listening on port 22. If it is configured for another port, allow that port instead or restore the intended SSH configuration.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
-
Check the client’s destination: make sure the SSH client is connecting to the correct host and port.
-
Check upstream filtering and routing: a router firewall may also need an SSH allowance and a NAT rule forwarding the connection to the server. Ubuntu’s SSH guidance explains this router-side requirement. Cloud security groups, provider firewalls, and load balancers may impose additional controls; their exact settings depend on the deployment.
-
Recheck the source restriction: if you used a host or subnet rule, confirm that the remote client’s observed source address falls within it.
Quick Recap
Bestseller No. 1Bestseller No. 2Bestseller No. 4
Commands at a glance
| Purpose | Command |
|---|---|
| Allow inbound SSH on TCP 22 | sudo ufw allow 22/tcp |
| Allow SSH by service name | sudo ufw allow ssh |
| Enable UFW | sudo ufw enable |
| Show detailed status | sudo ufw status verbose |
| List numbered rules | sudo ufw status numbered |
| Preview an allow rule | sudo ufw --dry-run allow 22/tcp |
| Remove the allow rule | sudo ufw delete allow 22/tcp |
| Rate-limit SSH connections | sudo ufw limit 22/tcp |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

