UFW

Uncomplicated FireWall

Installation

sudo apt install ufw

Configuration

#!/usr/bin/env bash

LAN_NETWORK="192.168.2.0/24"

# stop & reset
sudo ufw disable
sudo ufw reset

# defaults
sudo ufw default deny incoming
sudo ufw default allow outgoing

# config
# .0/24 means only specify 24 Bits / the first 3 numbers -> .0 is ignored
sudo ufw allow in from "${LAN_NETWORK}" to any port 22 proto tcp comment 'LAN - SSH'
sudo ufw allow in from "${LAN_NETWORK}" to any port 445 proto tcp  comment 'LAN - Samba'

sudo ufw allow in 80/tcp comment 'WWW - HTTP -> NGINX'
sudo ufw allow in 443/tcp comment 'WWW - HTTPS -> NGINX'

sudo ufw allow in to any port 8100 proto tcp from "${LAN_NETWORK}" comment 'LAN - Gunicorn'
sudo ufw allow in to any port 8200 proto tcp from "${LAN_NETWORK}" comment 'LAN - Otterwiki/Gunicorn'
sudo ufw allow in to any port 8300 proto tcp from "${LAN_NETWORK}" comment 'LAN - Django/Development'

# start
sudo ufw enable

# show
sudo ufw status verbose
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9