# Locked out after a firewall change: how to get back in

> Lost SSH or Remote Desktop after changing ufw, nftables, Windows Firewall or the SSH port? Get back in through the console, undo the rule, prevent a repeat.

Difficulty: Intermediate\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025

It happens to every administrator once: you enable a firewall, tighten a rule or move SSH to another port, and your connection drops. The server is fine; it just no longer lets you in. This guide gets you back in through the console and shows how to change firewalls safely.

## Before you start

You need a way in that does not depend on the network rule you broke:

- **Web console:** if your service page shows a **Web console** button (in the **Actions** menu or the **Manage** card), it opens the server's screen in your browser.
- **IPMI:** on dedicated servers where the plan includes a remote management interface.
- **No console:** open a ticket (see the end of this guide).

Sign in on the console as `root` or your sudo user. Typing is done through the console window; pasting may not work, so prefer short commands.

## Undo the change

**ufw**

Allow SSH again and check the result:

```bash
sudo ufw allow OpenSSH
sudo ufw status numbered
```

If you are unsure what went wrong, turn the firewall off for the moment, reconnect over SSH and fix the rules from there:

```bash
sudo ufw disable
```
**nftables**

Remove all rules from the running system:

```bash
sudo nft flush ruleset
```

This lasts until the next restart. Fix `/etc/nftables.conf`, check it with `sudo nft -c -f /etc/nftables.conf` and load it with `sudo nft -f /etc/nftables.conf`, or the old rules return at boot.
**firewalld**

Reload the saved configuration, or add SSH back to the zone:

```bash
sudo firewall-cmd --reload
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --reload
```
**Windows**

In an administrator PowerShell window on the console, enable the built-in Remote Desktop rules:

```powershell
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
```

If you made many changes, reset Windows Defender Firewall to its defaults. This removes all your own rules:

```powershell
netsh advfirewall reset
```

**Verify:** from your own computer, `nc -vz 203.0.113.10 22` (or `Test-NetConnection 203.0.113.10 -Port 3389` for Remote Desktop) reports the port as open, and you can connect again.

## If you changed the SSH port

Check which port SSH really listens on, from the console:

```bash
sudo ss -tlnp | grep -i ssh
sudo sshd -T | grep -i '^port'
```

- Make sure the firewall allows that port, for example `sudo ufw allow 2222/tcp`.
- **Ubuntu:** SSH is socket-activated. After changing `Port`, run `sudo systemctl daemon-reload` and `sudo systemctl restart ssh.socket`.
- **Debian:** restart the service with `sudo systemctl restart ssh`.

Then connect with `ssh -p 2222 alex@203.0.113.10`.

## If Fail2ban or CrowdSec banned you

Many failed attempts while you were testing can get your own IP address banned. From the console:

```bash
sudo fail2ban-client set sshd unbanip 198.51.100.7
sudo cscli decisions delete --ip 198.51.100.7
```

Use the command for the tool you run, with your own public IP address.

## Change firewalls safely next time

1. **Allow your access first.** Add the rule for SSH (or Remote Desktop) before you enable the firewall or set a default deny policy.
2. **Preview.** `sudo ufw --dry-run enable` shows what ufw would do without applying it. For nftables, `sudo nft -c -f /etc/nftables.conf` checks the syntax.
3. **Keep a session open.** Test with a second connection before you close the first.
4. **Schedule an automatic undo.** Before a risky change, start a timer that removes the rules in five minutes:

```bash
sudo systemd-run --on-active=5min /usr/sbin/ufw disable
```

For nftables use `/usr/sbin/nft flush ruleset` instead. If everything works, cancel the timer: `systemctl list-timers` shows its name (it starts with `run-`), and `sudo systemctl stop` followed by that name cancels it.

## When to open a ticket

If your service page has no console, or the console does not work, open a ticket with the server selected under **Related Service**. Write exactly what you changed (the commands you ran, the new SSH port) and from which IP address you connect. Do not include passwords in the ticket subject.

## Next steps

- Build firewall rules that will not lock you out: [ufw](/guides/ufw-firewall), [nftables](/guides/nftables-firewall), [Windows Defender Firewall](/guides/windows-firewall).
- Other SSH errors: [SSH connection problems](/guides/ssh-connection-problems).

## Frequently asked questions

### My SSH session froze right after I enabled the firewall. Is the server broken?

Almost certainly not. The firewall now drops your SSH traffic because no rule allows it. Use the console to allow SSH or turn the firewall off, then reconnect.

### I have no console on my service page. What can I do?

Open a support ticket with the server selected and describe exactly what you changed. Do not keep retrying the connection, which can trigger additional blocks.

### How do I avoid this next time?

Allow SSH or Remote Desktop before you enable the firewall, keep your current session open while you test a second one, and schedule an automatic rollback before risky changes.

### I changed the SSH port and cannot connect. Is it the firewall?

Often both: the new port must be allowed in the firewall, and on Ubuntu the SSH socket must be restarted after the change. Connect through the console and check which port sshd listens on.

### Does disabling the firewall leave the server unprotected?

For the moment, yes. Turn it off only to get back in, fix the rules, and turn it on again within minutes.

---

Source: <https://hyperdc.com/guides/troubleshooting/locked-out-after-firewall-change>\
Updated: 2026-10-09
