ufw-limit
Rate-limit connections through Uncomplicated Firewall
TLDR
SYNOPSIS
ufw [--dry-run] limit [rule]
DESCRIPTION
ufw limit adds a rate-limit rule to Uncomplicated Firewall. It is a ufw subcommand, not a separate binary. Matching connections are normally allowed; if one IP address tries to open 6 or more connections within 30 seconds, further attempts from that address are denied. The intended use is slowing brute-force logins on services such as SSH (`ufw limit ssh/tcp` or `ufw limit 22/tcp`).Rules can be simple port limits, application profiles (`ufw limit OpenSSH`), or full five-tuple style rules with source, destination, port, protocol, and interface. `ufw status` prints these as LIMIT. Remove a rule with `ufw delete limit ...` or by number after `ufw status numbered`.`ufw route limit` applies the same rate limit to forwarded traffic rather than traffic destined for the local host.
PARAMETERS
limit
Insert a rate-limit rule: matching traffic is allowed until one source IP opens 6 or more connections within 30 seconds, after which further attempts from that IP are deniedport[/protocol]
Simple form: port number, optional /tcp or /udpfrom address
Match source address or network (CIDR)to address
Match destination addressport port
Destination port (or range) when using full rule syntaxproto protocol
Protocol: tcp, udp, gre, etc.in / out
Direction of trafficon interface
Limit the rule to a network interfacecomment 'text'
Attach a human-readable comment to the rule--dry-run
Show what would change without applying it
INSTALL
CAVEATS
Requires root or sudo. Rate limiting is per source IP over a 30-second window of 6 new connections; it is not a general bandwidth cap and does not replace fail2ban-style bans. An existing session can still be locked out if later attempts trip the limit while you are connecting from the same address. Application profile names must match installed profiles under `/etc/ufw/applications.d/`. Prefer `--dry-run` before changing rules on a remote host.
HISTORY
Part of ufw (Uncomplicated Firewall), the Ubuntu-originated frontend for iptables/nftables.
SEE ALSO
ufw(8), ufw-allow(8), ufw-deny(8), ufw-delete(8), ufw-enable(8), ufw-status(8), iptables(8), nftables(8)
