Blocking Access to Private Networks on Ubuntu Using UFW

8 min readUpdated December 2, 2025

You may suddenly start receiving complaints from the data center about private network scanning even though you did not intend to do this. To prevent such outbound connections, you can block private networks with the ufw firewall.

#Installing ufw

First, check whether ufw is installed on your server and install it if needed.

bash
sudo apt install ufw
Installing ufw on the server

Before enabling the firewall, open the required ports so you do not lose access to your services. In most cases, you should allow SSH, HTTP, and HTTPS.

bash
sudo ufw allow 22 sudo ufw allow 80 sudo ufw allow 443

After that, enable the firewall.

bash
sudo ufw enable
Enabling ufw

You can check the current firewall status with the following command.

bash
sudo ufw status
Checking ufw status

#Blocking private networks

Now you can block private networks to prevent any outbound connections to them from your server.

The following ranges are treated as private or special-use networks:

  • 10.0.0.0/8
  • 172.16.0.0/12
  • 192.168.0.0/16
  • 100.64.0.0/10
  • 198.18.0.0/15
  • 169.254.0.0/16

To block these ranges, add the following rules.

bash
sudo ufw deny out from any to 10.0.0.0/8 sudo ufw deny out from any to 172.16.0.0/12 sudo ufw deny out from any to 192.168.0.0/16 sudo ufw deny out from any to 100.64.0.0/10 sudo ufw deny out from any to 198.18.0.0/15 sudo ufw deny out from any to 169.254.0.0/16

After adding the rules, verify that they are present.

bash
sudo ufw status # Or use iptables iptables-save
Checking blocking rules in ufw

If you try to access an address from a blocked range, the connection will fail. For example, you can test this with .

bash
ping 198.18.22.62
Failed access to a blocked network

This completes the private network blocking setup.

#Unblocking networks if required

If you later need to restore access to one of the blocked networks, first display the numbered list of current ufw rules.

bash
sudo ufw status numbered
Numbered list of ufw rules

Then delete the required rule by its number. Replace with the actual number from the previous command output.

bash
sudo ufw delete N

For example, you can remove rule 7.

bash
sudo ufw delete 7
Deleting a ufw rule by number

After removing the rule, access to the corresponding address will no longer be restricted.

Access check after removing the rule

You now know how to block and unblock your server access to private networks with ufw.

Did not find the answer? We are online 24/7.Contact support