_posts/ufw: typo fixes & add teredo

This commit is contained in:
Aminda Suomalainen 2015-09-06 13:04:16 +03:00
parent 9cbdd67a16
commit 5e456c114f

View File

@ -24,6 +24,7 @@ systemctl enable ufw && systemctl start ufw
ufw enable ufw enable
ufw reject 113/tcp ufw reject 113/tcp
ufw allow from 172.16.0.0/16 to any port 631 ufw allow from 172.16.0.0/16 to any port 631
ufw allow 3544/udp
ufw allow from 172.16.0.0/16 to any port 5353 proto udp ufw allow from 172.16.0.0/16 to any port 5353 proto udp
ufw allow from 173.16.0.0/16 to any port 9091 proto tcp ufw allow from 173.16.0.0/16 to any port 9091 proto tcp
ufw allow from 172.16.0.0/16 to any port 17500 proto tcp ufw allow from 172.16.0.0/16 to any port 17500 proto tcp
@ -31,11 +32,11 @@ ufw allow 60000:61000/udp
``` ```
* 22 TCP/ssh — Prevent more than 6 connections in 30 seconds to the SSH * 22 TCP/ssh — Prevent more than 6 connections in 30 seconds to the SSH
port and it's the first command as you don't want to lock yourself out of port and it's the first command as you don't want to lock yourself out
and it's the first command as you don't want to lock yourself out of of it.
* Deny incoming connections unless the port has been whitelisted. * Deny incoming connections unless the port has been whitelisted.
* Allow all outgoing connections, keeping list of authorized ports would be * Allow all outgoing connections, keeping list of authorized ports would
too much for me. be too much for me.
* Start ufw on boot and now (I am not sure if this step is required, but * Start ufw on boot and now (I am not sure if this step is required, but
better safe than sorry). better safe than sorry).
* Put the firewall in force. * Put the firewall in force.
@ -45,8 +46,10 @@ ufw allow 60000:61000/udp
allow this instead. allow this instead.
* 631 both/cups — Allow access to cups for printer sharing from local * 631 both/cups — Allow access to cups for printer sharing from local
network network
* 5353 UDP/mdns/Avahi — used for `.local` addresses and probably not needed * 3544 udp/miredo — Sadly native IPv6 isn't everywhere, neither is 6rd
outside local network with every ISP or proper tunnel.
* 5353 UDP/mdns/Avahi — used for `.local` addresses and probably not
needed outside local network
* 9091 TCP/transmission web interface — also something I want to access * 9091 TCP/transmission web interface — also something I want to access
from LAN. This seems risky too, but risks can be limited by only from LAN. This seems risky too, but risks can be limited by only
using this rule with static hosts. using this rule with static hosts.