XOA restrict access through UFW
VKB-1099How-to
- 📦 Applies to
- Xen Orchestra
- 🗓️ Created
- 2024-03-14
- 🔄 Updated
- 2026-10-10
- 🏷️ Tags
Environment
- A Xen Orchestra Appliance (XOA), accessed via SSH with root privileges.
Procedure
-
Allow each IP address that must keep access to the web interface:
# sudo -s # ufw allow from <allowed_ip> to any port 80 # ufw allow from <allowed_ip> to any port 443
Repeat for every address that needs access.
-
After that you need to remove all other access with:
# ufw deny 80/tcp # ufw deny 443/tcp
-
If you need to delete a rule, list the rules first, then delete by number:
# ufw status numbered # ufw delete <rule number>
-
For the change to take place, use:
# ufw reload
Verification
Run ufw status numbered: the allow rules for your IPs on ports 80 and 443 and the deny rules for all other access are listed.
Was this page helpful?