Skip to content

Add UFW and Fail2ban security tutorial - #1545

Closed
iadminiserversupport wants to merge 1 commit into
hetzneronline:masterfrom
iadminiserversupport:secure-hetzner-cloud-server-ufw-fail2ban
Closed

iadminiserversupport wants to merge 1 commit into
hetzneronline:masterfrom
iadminiserversupport:secure-hetzner-cloud-server-ufw-fail2ban

Conversation

@iadminiserversupport

@iadminiserversupport iadminiserversupport commented Sep 27, 2026 •

Copy link
Copy Markdown

Description

Type of change

  • New tutorial
  • Update to an existing tutorial
  • Translation
  • Repository / tooling change

Checklist

  • I have read the contribution guidelines.
  • No tutorial about the exact same topic exists yet (checked community.hetzner.com and open PRs).
  • The folder name, the path and the slug in the front matter match.
  • All metadata fields required by the metadata schema are present.
  • At least one file is English (01.en.md).
  • The license block is included at the end of every tutorial file, with my name and email filled in.
  • Images (if any) are stored in an images/ subfolder next to the tutorial.
  • Any external software, Docker image or Terraform module used is free, open source and trusted.
  • This contribution is original and was not primarily or entirely generated by AI.

Contributor's Certificate of Origin

I have read and understood the Contributor's Certificate of Origin available at the end of
https://raw.githubusercontent.com/hetzneronline/community-content/master/tutorial-template.md
and I hereby certify that I meet the contribution criteria described in it.

Signed-off-by: David B iserverseo@gmail.com

@iadminiserversupport
iadminiserversupport marked this pull request as draft September 27, 2026 06:24
@iadminiserversupport

Copy link
Copy Markdown
Author

David B iserverseo@gmail.com

@iadminiserversupport
iadminiserversupport marked this pull request as ready for review September 27, 2026 06:26
@maximilianfeix
maximilianfeix self-requested a review October 1, 2026 06:18
@maximilianfeix

Copy link
Copy Markdown
Collaborator

Hi @iadminiserversupport , thanks for putting this together!

Before going into the details, there's one bigger issue: we already have a published tutorial on pretty much the same topic, Securing SSH on Ubuntu with UFW and Fail2ban (added in June). It covers UFW + Fail2ban for SSH and even goes a step further by making Fail2ban ban through UFW. The UFW basics are also covered in Simple Firewall Management with UFW. As it stands, this tutorial doesn't really add something new on top of those two.

If you'd like to keep working on it, one angle that isn't covered yet is the Hetzner Cloud Firewall itself: when to use it vs. a host firewall like UFW, how the two work together, and what a sensible setup looks like. Your title already says "Hetzner Cloud Server", so that would fit nicely. Let me know if that sounds interesting to you.

Either way, a few technical things I noticed while going through the file:

Front matter
The metadata block is broken right now. The file starts with an empty block of keys, the real metadata only follows after that, and it's closed with -------------- instead of ---. Because of this the front matter isn't recognized at all (that's also where most of the markdownlint errors come from). It should look like this:

---
SPDX-License-Identifier: MIT
path: "/tutorials/secure-hetzner-cloud-server-ufw-fail2ban"
...
---

A few fields also don't pass our schema:

  • author_img can't be empty, please use https://avatars.githubusercontent.com/u/315555854
  • header_img should be one of header-1 to header-9
  • cta: "product" isn't a valid value, cloud would make sense here

License block
The sign-off at the bottom still says David B <YOUR-EMAIL-HERE>. Please add your actual email address there.

Content

  • The intro still contains a couple of sentences from the template that are meant for authors ("Do not use an actual public IP address in this tutorial...", "The examples use the standard placeholder values..."). Those can be removed.
  • In step 2, 203.0.113.1 is the example client IP. For connecting to the server, please use <10.0.0.1>.
  • In step 3, UFW is enabled first and the default policies are set afterwards, and ufw allow OpenSSH shows up twice. I'd set the defaults, allow SSH, and then enable UFW. Checking the listening services (step 4) would also make more sense before opening any ports.
  • Steps 7–9 and the "Common Mistakes" section repeat quite a few commands from earlier. It'd be great to cut some of that and instead explain a bit more why things are done the way they are, e.g. what the jail.local values actually mean for the user.

PR checklist
I noticed that the checkbox about the contribution being original and not primarily generated by AI is left unchecked. Could you clarify that? As mentioned in our contribution guidelines, we can only accept tutorials that are written by the author.

Thanks again, and let me know how you'd like to proceed!

@maximilianfeix maximilianfeix added Existing tutorial Changes on an existing tutorial duplicate This issue or pull request already exists and removed Existing tutorial Changes on an existing tutorial labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

duplicate This issue or pull request already exists

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants