Skip to content

TroubleshootingConnection problems

Locked out after a firewall change: how to get back in

Lost SSH or Remote Desktop after changing ufw, nftables, Windows Firewall or the SSH port? Get back in through the console, undo the rule, prevent a repeat.

  • Intermediate
  • 10 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Undo the change
  3. If you changed the SSH port
  4. If Fail2ban or CrowdSec banned you
  5. Change firewalls safely next time
  6. When to open a ticket
  7. Next steps

It happens to every administrator once: you enable a firewall, tighten a rule or move SSH to another port, and your connection drops. The server is fine; it just no longer lets you in. This guide gets you back in through the console and shows how to change firewalls safely.

Before you start

You need a way in that does not depend on the network rule you broke:

  • Web console: if your service page shows a Web console button (in the Actions menu or the Manage card), it opens the server's screen in your browser.
  • IPMI: on dedicated servers where the plan includes a remote management interface.
  • No console: open a ticket (see the end of this guide).

Sign in on the console as root or your sudo user. Typing is done through the console window; pasting may not work, so prefer short commands.

Undo the change

ufw

Allow SSH again and check the result:

Bash
sudo ufw allow OpenSSH
sudo ufw status numbered

If you are unsure what went wrong, turn the firewall off for the moment, reconnect over SSH and fix the rules from there:

Bash
sudo ufw disable

nftables

Remove all rules from the running system:

Bash
sudo nft flush ruleset

This lasts until the next restart. Fix /etc/nftables.conf, check it with sudo nft -c -f /etc/nftables.conf and load it with sudo nft -f /etc/nftables.conf, or the old rules return at boot.

firewalld

Reload the saved configuration, or add SSH back to the zone:

Bash
sudo firewall-cmd --reload
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --reload

Windows

In an administrator PowerShell window on the console, enable the built-in Remote Desktop rules:

PowerShell
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"

If you made many changes, reset Windows Defender Firewall to its defaults. This removes all your own rules:

PowerShell
netsh advfirewall reset

Verify: from your own computer, nc -vz 203.0.113.10 22 (or Test-NetConnection 203.0.113.10 -Port 3389 for Remote Desktop) reports the port as open, and you can connect again.

If you changed the SSH port

Check which port SSH really listens on, from the console:

Bash
sudo ss -tlnp | grep -i ssh
sudo sshd -T | grep -i '^port'
  • Make sure the firewall allows that port, for example sudo ufw allow 2222/tcp.
  • Ubuntu: SSH is socket-activated. After changing Port, run sudo systemctl daemon-reload and sudo systemctl restart ssh.socket.
  • Debian: restart the service with sudo systemctl restart ssh.

Then connect with ssh -p 2222 [email protected].

If Fail2ban or CrowdSec banned you

Many failed attempts while you were testing can get your own IP address banned. From the console:

Bash
sudo fail2ban-client set sshd unbanip 198.51.100.7
sudo cscli decisions delete --ip 198.51.100.7

Use the command for the tool you run, with your own public IP address.

Change firewalls safely next time

  1. Allow your access first. Add the rule for SSH (or Remote Desktop) before you enable the firewall or set a default deny policy.
  2. Preview. sudo ufw --dry-run enable shows what ufw would do without applying it. For nftables, sudo nft -c -f /etc/nftables.conf checks the syntax.
  3. Keep a session open. Test with a second connection before you close the first.
  4. Schedule an automatic undo. Before a risky change, start a timer that removes the rules in five minutes:
Bash
sudo systemd-run --on-active=5min /usr/sbin/ufw disable

For nftables use /usr/sbin/nft flush ruleset instead. If everything works, cancel the timer: systemctl list-timers shows its name (it starts with run-), and sudo systemctl stop followed by that name cancels it.

When to open a ticket

If your service page has no console, or the console does not work, open a ticket with the server selected under Related Service. Write exactly what you changed (the commands you ran, the new SSH port) and from which IP address you connect. Do not include passwords in the ticket subject.

Next steps

Frequently asked questions

My SSH session froze right after I enabled the firewall. Is the server broken?

Almost certainly not. The firewall now drops your SSH traffic because no rule allows it. Use the console to allow SSH or turn the firewall off, then reconnect.

I have no console on my service page. What can I do?

Open a support ticket with the server selected and describe exactly what you changed. Do not keep retrying the connection, which can trigger additional blocks.

How do I avoid this next time?

Allow SSH or Remote Desktop before you enable the firewall, keep your current session open while you test a second one, and schedule an automatic rollback before risky changes.

I changed the SSH port and cannot connect. Is it the firewall?

Often both: the new port must be allowed in the firewall, and on Ubuntu the SSH socket must be restarted after the change. Connect through the console and check which port sshd listens on.

Does disabling the firewall leave the server unprotected?

For the moment, yes. Turn it off only to get back in, fix the rules, and turn it on again within minutes.

Sources

Wachtwoord genereren

Please confirm