Blame

d490ad Niklas Polke 2026-08-03 16:07:13
Create UFW
1
# UFW
2
Uncomplicated FireWall
3
4
## Installation
5
```bash
6
sudo apt install ufw
7
```
8
9
## Configuration
10
11
:::warning
12
If port 22/tcp is not allowed, ssh will be terminated and no connection will be possible any more!
13
:::
14
```bash
f8d430 Niklas Polke 2026-08-06 23:47:25
Update with content of ufw-init.sh
15
#!/usr/bin/env bash
16
17
LAN_NETWORK="192.168.2.0/24"
18
19
# stop & reset
20
sudo ufw disable
21
sudo ufw reset
22
23
# defaults
d490ad Niklas Polke 2026-08-03 16:07:13
Create UFW
24
sudo ufw default deny incoming
25
sudo ufw default allow outgoing
26
f8d430 Niklas Polke 2026-08-06 23:47:25
Update with content of ufw-init.sh
27
# config
28
# .0/24 means only specify 24 Bits / the first 3 numbers -> .0 is ignored
29
sudo ufw allow in from "${LAN_NETWORK}" to any port 22 proto tcp comment 'LAN - SSH'
30
sudo ufw allow in from "${LAN_NETWORK}" to any port 445 proto tcp comment 'LAN - Samba'
d490ad Niklas Polke 2026-08-03 16:07:13
Create UFW
31
f8d430 Niklas Polke 2026-08-06 23:47:25
Update with content of ufw-init.sh
32
sudo ufw allow in 80/tcp comment 'WWW - HTTP -> NGINX'
33
sudo ufw allow in 443/tcp comment 'WWW - HTTPS -> NGINX'
34
35
sudo ufw allow in to any port 8100 proto tcp from "${LAN_NETWORK}" comment 'LAN - Gunicorn'
36
sudo ufw allow in to any port 8200 proto tcp from "${LAN_NETWORK}" comment 'LAN - Otterwiki/Gunicorn'
37
sudo ufw allow in to any port 8300 proto tcp from "${LAN_NETWORK}" comment 'LAN - Django/Development'
38
39
# start
d490ad Niklas Polke 2026-08-03 16:07:13
Create UFW
40
sudo ufw enable
f8d430 Niklas Polke 2026-08-06 23:47:25
Update with content of ufw-init.sh
41
42
# show
43
sudo ufw status verbose
d490ad Niklas Polke 2026-08-03 16:07:13
Create UFW
44
```