On a cloud server, packets meet a firewall before they reach your machine. On AWS 24 it is the security group, rules attached to the instance's network interface and enforced by the platform, outside the operating system: ufw 280 status cannot see it and sudo cannot change it. Azure 6 calls the equivalent a network security group, Google Cloud 1 calls it VPC firewall rules. Three properties matter:
A new security group has no inbound rules and one outbound rule allowing everything, so nothing reaches the instance until you allow it.
Rules only allow, and where two cover the same port the more permissive wins. Like the nftables 40,292 policy in firewalld and nftables, a group is stateful, so replies need no rule.
A source can be another security group, which is how a database admits 3306 from the web servers only.
From the CLI, aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 443 --cidr 0.0.0.0/0 opens HTTPS to the world (it needs an AWS account, so it was not run here).
The two layers must agree, and a port closed in either one times out in exactly the same way, which is why the checklist in Port Closed? checks both. Keep the host firewall anyway: it survives a carelessly edited security group and a move to a provider without one. Security Groups builds the security group for a real EC2 24 web server.