Blame
|
1 | # UFW |
||||||
| 2 | Uncomplicated FireWall |
|||||||
| 3 | ||||||||
| 4 | ## Installation |
|||||||
| 5 | ```bash |
|||||||
| 6 | sudo apt install ufw |
|||||||
| 7 | ``` |
|||||||
| 8 | ||||||||
| 9 | ## Configuration |
|||||||
| 10 | ||||||||
| 11 | :::warning |
|||||||
| 12 | If port 22/tcp is not allowed, ssh will be terminated and no connection will be possible any more! |
|||||||
| 13 | ::: |
|||||||
| 14 | ```bash |
|||||||
|
15 | #!/usr/bin/env bash |
||||||
| 16 | ||||||||
| 17 | LAN_NETWORK="192.168.2.0/24" |
|||||||
| 18 | ||||||||
| 19 | # stop & reset |
|||||||
| 20 | sudo ufw disable |
|||||||
| 21 | sudo ufw reset |
|||||||
| 22 | ||||||||
| 23 | # defaults |
|||||||
|
24 | sudo ufw default deny incoming |
||||||
| 25 | sudo ufw default allow outgoing |
|||||||
| 26 | ||||||||
|
27 | # config |
||||||
| 28 | # .0/24 means only specify 24 Bits / the first 3 numbers -> .0 is ignored |
|||||||
| 29 | sudo ufw allow in from "${LAN_NETWORK}" to any port 22 proto tcp comment 'LAN - SSH' |
|||||||
| 30 | sudo ufw allow in from "${LAN_NETWORK}" to any port 445 proto tcp comment 'LAN - Samba' |
|||||||
|
31 | |||||||
|
32 | sudo ufw allow in 80/tcp comment 'WWW - HTTP -> NGINX' |
||||||
| 33 | sudo ufw allow in 443/tcp comment 'WWW - HTTPS -> NGINX' |
|||||||
| 34 | ||||||||
| 35 | sudo ufw allow in to any port 8100 proto tcp from "${LAN_NETWORK}" comment 'LAN - Gunicorn' |
|||||||
| 36 | sudo ufw allow in to any port 8200 proto tcp from "${LAN_NETWORK}" comment 'LAN - Otterwiki/Gunicorn' |
|||||||
| 37 | sudo ufw allow in to any port 8300 proto tcp from "${LAN_NETWORK}" comment 'LAN - Django/Development' |
|||||||
| 38 | ||||||||
| 39 | # start |
|||||||
|
40 | sudo ufw enable |
||||||
|
41 | |||||||
| 42 | # show |
|||||||
| 43 | sudo ufw status verbose |
|||||||
|
44 | ``` |
||||||
