Skip to main content

XOA restrict access through UFW

VKB-1099How-to
📦 Applies to
Xen Orchestra
🗓️ Created
2024-03-14
🔄 Updated
2026-10-10

Environment​

  • A Xen Orchestra Appliance (XOA), accessed via SSH with root privileges.

Procedure​

  1. Allow each IP address that must keep access to the web interface:

    root@dom0
    # sudo -s
    # ufw allow from <allowed_ip> to any port 80
    # ufw allow from <allowed_ip> to any port 443

    Repeat for every address that needs access.

  2. After that you need to remove all other access with:

    root@dom0
    # ufw deny 80/tcp
    # ufw deny 443/tcp
  3. If you need to delete a rule, list the rules first, then delete by number:

    root@dom0
    # ufw status numbered
    # ufw delete <rule number>
  4. For the change to take place, use:

    root@dom0
    # ufw reload

Verification​

Run ufw status numbered: the allow rules for your IPs on ports 80 and 443 and the deny rules for all other access are listed.