Ask Steves · Daily notes · VPS, 20% off · AI Profit Lab · SEO · Money Hub

3 October 2026 · One command a day

How do I list ufw firewall rules with numbers on Ubuntu?

The ufw status numbered command lists every rule in the Ubuntu firewall, with a number next to each one. The plain ufw status shows the same rules without numbers. You reach for the numbered form when you want to delete or insert a rule, because ufw refers to rules by their position in the list.

The command

sudo ufw status numbered

sudo is needed because ufw reads the live firewall state, which only root can see. ufw is the Uncomplicated Firewall, the front end to netfilter that ships with Ubuntu. status asks whether the firewall is on and what rules it holds. numbered adds an index in square brackets to each line, and that index is what ufw delete and ufw insert expect.

What you will see

Status: active

     To                         Action      From
     --                         ------      ----
[ 1] 22/tcp                     ALLOW IN    Anywhere
[ 2] 80/tcp                     ALLOW IN    Anywhere
[ 3] 443/tcp                    ALLOW IN    Anywhere
[ 4] 3000/tcp                   ALLOW IN    127.0.0.1
[ 5] 22/tcp (v6)                ALLOW IN    Anywhere (v6)
[ 6] 80/tcp (v6)                ALLOW IN    Anywhere (v6)
[ 7] 443/tcp (v6)               ALLOW IN    Anywhere (v6)

The first line tells you whether the firewall is actually running. Each rule has a number, the port or service it covers, the action, and where traffic may come from. Rules are checked from the top down and the first match wins. Here SSH, HTTP and HTTPS are open to the world, port 3000 only accepts connections from the machine itself, and the IPv6 copies sit at the end. To remove rule four you would run sudo ufw delete 4 and confirm with y.

When to use it

Watch out for

The numbers shift as soon as you delete a rule. If you remove rule two, the old rule three becomes rule two. People who delete several rules in one go using the numbers from a single listing often remove the wrong ones. Either delete from the highest number downwards, or run sudo ufw status numbered again before each delete. Deletion asks you to confirm, so read the rule it prints back before you press y.

Questions people ask

Why does it say Status: inactive?

The firewall is installed but not switched on, so none of the rules apply and every listening port is open. Before you run sudo ufw enable, make sure a rule allows port 22, or you will lock yourself out of SSH.

Why can I reach a Docker container on a port ufw blocks?

Docker writes its own rules into iptables ahead of ufw when you publish a port with -p, so ufw never sees that traffic. Bind published ports to 127.0.0.1 and let nginx handle the outside, or do not publish ports that should stay private.

Reading and editing the firewall by rule number is only possible on a server you control, where you hold root and nothing sits between you and the kernel. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.

Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.

GET A VPS, 20% OFF →

Affiliate link.

More daily notes: How do I list all my SSL certificates and their expiry dates with certbot? · How do I test that certbot can renew my SSL certificate? · How do I check a website's SSL certificate from the command line?