Network-layer access control.
UFW rule management with per-rule comments, audit logging, and drift detection. Add a port, allow an IP, deny a CIDR — without SSH.
Firewall (UFW)
6 rules · status: active
- [1]allow22/tcp · from anyinSSH ops access
- [2]allow80/tcp · from anyinHTTP
- [3]allow443/tcp · from anyinHTTPS
- [4]allow5432/tcp · from 10.0.0.0/8inPostgres VPC only
- [5]deny23/tcp · from anyinBlock telnet
- [6]deny185.220.101.34/32inAI block_ip · brute force
How it works
What happens under the hood.
- 01
Read current rules
Agent runs `ufw status numbered` and surfaces the rule list in the panel.
- 02
Add via panel or AI
Allow port 5432 from your office IP — through a click or by asking the AI Assistant.
- 03
Approval gate
Adding a firewall rule is a tier-Approve operation. Even the AI prompts you before changing UFW state.
- 04
Audit + drift
Every rule change is logged. Drift detection alerts you if someone edits ufw outside the panel.
What you get
The capabilities that ship.
Allow / deny rules
Per-port, per-IP, per-CIDR. Both inbound and outbound supported.
Per-rule comments
Every rule carries a why-string so the next operator (or you in 6 months) knows why it exists.
Block IP fast
AI tool `block_ip` for incident response — drops a deny rule in seconds when an abuser is hitting your box.
Drift-tracked
Anyone edits /etc/ufw/* outside the panel and you'll see it in drift findings.
FAQ
Common questions.
What if my server uses iptables / nftables directly?
Is this just a wrapper around `ufw allow`?
Your fleet deserves better.
Get started in minutes.
Deploy agents on your servers, connect securely, and take full control. Start free, upgrade when ready.
- 7-day free trial
- No credit card
- Cancel anytime
