The Port Authorization Vector
When deploying a production Ubuntu server, the machine is mathematically bombarded by thousands of automated SSH brute-force attempts and port scanners within minutes of coming online. The Linux kernel relies on `iptables` (and its modern front-end, UFW – Uncomplicated Firewall) to act as a cryptographic barricade, systematically dropping all incoming network packets that do not match a specific, pre-authorized routing rule. If a client reports they cannot access your newly deployed Nginx web server on Port 80, you must instantly interrogate the UFW daemon to extract the active matrix of allowed and denied ports.
How to Check Firewall Status in Ubuntu
The `ufw` utility is installed by default on almost all modern Ubuntu Server distributions. Because interrogating the active firewall ruleset requires accessing secure kernel routing tables, all commands strictly demand root-level authorization.
1. Open your terminal application or connect to the server via SSH.
2. The Primary Diagnostic Execution (`ufw status`):
* This is the fastest method to ascertain whether the firewall daemon is actively running and blocking traffic.
* Type exactly:
sudo ufw status
* Press Enter and supply your cryptographic `sudo` password.
* Parsing the Data:
* If the terminal outputs simply: Status: inactive, the firewall daemon is mathematically disabled. The server is completely exposed to the open internet (or relying solely on a cloud provider’s external firewall). All ports are open.
* If the terminal outputs: Status: active, it will immediately follow with a dense table listing every specific port rule currently loaded into RAM (e.g., `80/tcp ALLOW Anywhere`, `22/tcp ALLOW Anywhere`).
3. The Verbose Interrogation Protocol:
* If you need deeper telemetry—specifically, to see the default routing policies (e.g., whether the firewall defaults to dropping or rejecting unauthorized packets) and the specific network interfaces being monitored.
* Type exactly:
sudo ufw status verbose
* Press Enter.
* The output will now include critical architectural data, such as: `Default: deny (incoming), allow (outgoing), disabled (routed)`.
4. The Numbered Rules Matrix (For Surgical Deletions):
* If you identify a rogue rule in the list (e.g., you accidentally allowed Port 3306 for a database and need to revoke it), you must list the rules mathematically by index number so you can target the deletion command.
* Type exactly:
sudo ufw status numbered
* Press Enter.
* The terminal will output the exact same table, but each rule will have a unique integer inside brackets (e.g., `[ 1] 22/tcp ALLOW IN Anywhere`). You can then surgically destroy that specific rule by typing `sudo ufw delete 1`.