Lorem ipsum dolor sit amet, consectetur adipiscing elit lobortis arcu enim urna adipiscing praesent velit viverra sit semper lorem eu cursus vel hendrerit elementum morbi curabitur etiam nibh justo, lorem aliquet donec sed sit mi dignissim at ante massa mattis.
Vitae congue eu consequat ac felis placerat vestibulum lectus mauris ultrices cursus sit amet dictum sit amet justo donec enim diam porttitor lacus luctus accumsan tortor posuere praesent tristique magna sit amet purus gravida quis blandit turpis.
At risus viverra adipiscing at in tellus integer feugiat nisl pretium fusce id velit ut tortor sagittis orci a scelerisque purus semper eget at lectus urna duis convallis. porta nibh venenatis cras sed felis eget neque laoreet suspendisse interdum consectetur libero id faucibus nisl donec pretium vulputate sapien nec sagittis aliquam nunc lobortis mattis aliquam faucibus purus in.
Nisi quis eleifend quam adipiscing vitae aliquet bibendum enim facilisis gravida neque. Velit euismod in pellentesque massa placerat volutpat lacus laoreet non curabitur gravida odio aenean sed adipiscing diam donec adipiscing tristique risus. amet est placerat in egestas erat imperdiet sed euismod nisi.
“Nisi quis eleifend quam adipiscing vitae aliquet bibendum enim facilisis gravida neque velit euismod in pellentesque massa placerat”
Eget lorem dolor sed viverra ipsum nunc aliquet bibendum felis donec et odio pellentesque diam volutpat commodo sed egestas aliquam sem fringilla ut morbi tincidunt augue interdum velit euismod eu tincidunt tortor aliquam nulla facilisi aenean sed adipiscing diam donec adipiscing ut lectus arcu bibendum at varius vel pharetra nibh venenatis cras sed felis eget dolor cosnectur drolo.
Every week at MNX solutions we handle issues from server security and patch management to system recovery and performance tuning. In this blog series, we will review a number of firewall best practices that you can implement today on your server infrastructure.First things first, do you utilize a firewall on your server? If your answer is "no" or you are not sure, this should be one of your top priorities.You have two major choices for a firewall: hardware or software.A quick note on hardware vs. software firewallsHardware firewalls can protect every machine on a local network (on the inside or DMZ area) whereas a host based firewall will typically only protect one server. One major advantage of a hardware firewall is a single point of configuration change to affect all systems behind the firewall.Software firewalls are typically installed on each host. This also means that a simple change, depending on how many machines you are working with, can be a complex task involving changes to each host.Each solution has pros and cons. You will need to defined your requirements to help you decide which solution should be used. Generally a layered approach, of using both a hardware firewall and a software firewall will provide you with the best level of protection. A layered approach may also provide protection in the event of a mis-configuration of the hardware or software firewall rules.At MNX Solutions, we utilize two solutions for software based firewalls: CSF and straight IPTables.CSF uses IPTables at the core, but simplifies the administration through configuration files and integration with control panels. CSF also provides additional advanced functionality such as:
Basic Firewall RulesBy default, you should deny all connections and allow only required connection. If you are running a web server with SSL and SSH access this would mean a base inbound ruleset of:* Open SSH port for my specific IP addresses* Open port 80 for all* Open port 443 for all* Deny everything else inboundThe main point is to ensure you are using some form of a firewall on your hosts. Contact us today if you need help implementing or managing any aspect of your server.
Click here for additional detail on our Linux server management solutions or request a proposal so you can start focusing on growing your business, rather than supporting your servers.