Firewall init
Firewall is used to keep a check on the incoming and outgoing connections.
We shall be using ufw (Uncomplicated Firewall) to close unwanted incoming connections from the Internet and allow outgoing ones.
It’s preferable to not use Scaleway servers, as something or the other used to get messed up on those. Digital Ocean and Vultr seem to do just fine.
Make sure this is the first thing you do when setting up a server. This is to ensure there is no data loss or time loss if anything goes wrong. There is a major chance of losing complete access to the server in case you don’t configure something properly. So make sure to backup your data locally or on another server to prevent any data loss.
Installation
apt install ufwConfiguration
Edit /etc/default/ufw and modify the policies:
DEFAULT_INPUT_POLICY="ACCEPT"DEFAULT_OUTPUT_POLICY="ACCEPT"DEFAULT_FORWARD_POLICY="ACCEPT"Append a drop-all rule to the INPUT chain. Edit /etc/ufw/after.rules, add this line just before the final COMMIT line:
-A ufw-reject-input -j DROPDisable ufw logging (this seems to cause issues with Scaleway’s default kernel):
ufw logging offFix permissions (seems to be necessary on some setups):
chmod 751 /etc/defaultchmod 751 /etcchmod 751 /usrBasic Setup
Setup a basic configuration to allow SSH, HTTPS and HTTP incoming:
ufw default deny incomingufw default allow outgoingufw allow sshufw allow 80/tcpufw allow 443/tcpufw enableIn a new terminal window check that you can still access your host via ssh.
Management
Check the configuration at any time:
ufw status verboseDisable the ufw configuration at any time:
sudo ufw disable