A well-configured firewall opens only the game and administration ports. This tool writes the commands for you for ufw, iptables, nftables or Windows, from a simple port list.
How to use the tool
Choose the firewall: ufw (Ubuntu/Debian), iptables, nftables or Windows netsh.
Enter your ports (one per line, with protocol) or add a game's ports.
Check the SSH port and, if needed, restrict to a source IP (for example for RCON).
Copy or download the script, read it, then run it while keeping an SSH session open.
Avoid locking yourself out
With the “default policy: deny everything” option, the script allows SSH first and then enables the firewall. If your SSH isn't on port 22, fix the field before running. Host firewalls (OVH, Hetzner, Scaleway…) and your router must also allow the same ports. With nftables, always validate the file with “nft -c -f” before applying. iptables rules here cover IPv4 only.
sudo ufw allow 22/tcp
sudo ufw allow 30120/tcp
sudo ufw allow 30120/udp
sudo ufw enableFrequently asked questions
- Should I open TCP, UDP or both?
- The one the game uses: see the ports checker. Without a protocol the tool generates both TCP and UDP, which opens more than needed: specify the protocol when you know it.
- Do the rules survive a reboot?
- ufw and Windows do. For iptables, install iptables-persistent and run netfilter-persistent save; for nftables, enable the nftables service with /etc/nftables.conf.
