Linux

Where Does UFW Store Firewall Rules?

UFW files user rules in user.rules files under /etc/ufw, managed through the ufw command rather than by hand.

Last updated

UFW fronts iptables with friendly commands and plain files. User rules land in user.rules with IPv6 twins in user6.rules, while framework files wrap them with before and after policies.

Evaluation order runs before, user, after, which the manpage states and newcomers ignore. Defaults live in a separate defaults file covering IPv6 and policy. The command writes the files; the files feed iptables-restore under the hood.

Where Linux stores this, by platform

Linux
/etc/ufw/user.rules

User added IPv4 rules live here with IPv6 twins in user6.rules. Manage through ufw commands; hand edits risk silent rejection.

Linux
/etc/default/ufw

High level defaults like IPv6 and policy live here. Framework before and after files wrap the user rules in evaluation order.

Frequently asked questions

Can I edit the rules files directly?

Use ufw allow and ufw deny commands, never hand edits. The files carry checksums and structure the parser expects. Manual changes risk silent rejection on reload.

Does status show everything?

No: ufw status shows only user added rules, not the before and after framework files. Full picture needs reading all three files plus defaults. The manpage documents the evaluation order explicitly.

Notice an outdated path? Let us know.