sudo ufw default deny incomingsudo ufw default allow outgoing# Allow SSH, HTTP, and HTTPSsudo ufw allow sshsudo ufw allow httpsudo ufw allow https# Check if the server is workingcurl -I http://your-server-ip# check for errorssudo journalctl -u ufw --no-pager | tail -n 20
Setup twingate
sudo ufw default deny incomingsudo ufw default allow outgoingsudo ufw allow out to any port 443 proto tcp # Allow outbound HTTPS (Twingate control traffic)sudo ufw allow out to any port 3478 proto udp # Allow STUN/TURN for WebRTC (Optional)sudo ufw allow out to any port 10000:65535 proto udp # Allow dynamic UDP for peer-to-peer