Firewall
What is Firewall?
A firewall looks at a packet: where it came from, where it goes, and which port it is. If a rule matches, it passes. If not, it is dropped. This is not a check inside the program. It is the network door. It does not encrypt. HTTPS is a separate topic.
What is Firewall used for?
It is for keeping only the needed port open on a server.
- Keeping the SSH port limited
- Opening 80 and 443 for the web
- Not exposing the database port
- Repeating a cloud security group
What can you do with Firewall?
With ufw you write a short rule. Running enable before you allow SSH can cut you off from the server. A security group in the cloud panel is a second door. If both are closed, traffic does not arrive.
Is Firewall hard to learn?
Opening one port is easy. The difficulty is the order: allow first, then enable. Mixing inbound and outbound traffic silences a service. A firewall does not fix a program mistake or a weak password.
Advantages and limits
Advantage: the number of open ports drops, and the rule is readable. Limit: it does not look inside encrypted traffic, and a wrong rule can lock you out. The app still has to do its own check.
Basic ideas
A port is a number. 22 is for SSH, 80 for HTTP, and 443 for HTTPS. Default deny closes everything else.
- ufw is a simple front on Ubuntu
- nftables is the lower level
- A security group is the cloud firewall
- allow from an IP can permit only one address
A short example
This order opens SSH and HTTPS first, then turns the firewall on. Change the SSH rule to match your port.
sudo ufw allow OpenSSH sudo ufw allow 443/tcp sudo ufw enable
Common questions
- Is a firewall an antivirus? No. It is a network rule.
- Does a firewall replace HTTPS? No. One chooses the port. The other encrypts the traffic.
- Is closing everything safe? It can also close your way in. Open the admin port first.