Skip to content
Back to skills

Firewall

ASecurity

Configure firewalls on servers and cloud providers with security best practices.

  • 17 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 6, 2026
devopsrustgodockerawsdebugginggitdatabasesecuritydocumentation

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill firewall --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Firewall?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Firewall
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-firewall/badge)](https://www.skillsdirectory.com/skills/clawic-firewall)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Firewall
slug: firewall
version: 1.0.0
description: Configure firewalls on servers and cloud providers with security best practices.
homepage: https://clawic.com/skills/firewall
metadata:
  clawdbot:
    emoji: πŸ›‘οΈ
    os:
    - linux
    - darwin
    - win32
    displayName: Firewall
---

# Firewall Rules

## Critical First Steps
- Allow SSH/remote access before enabling any firewall β€” enabling first locks you out
- Test access in a second session before closing the first β€” verify the rule actually works
- Know how to access provider console β€” it's the only way back if locked out

## Default Stance
- Default deny all incoming traffic β€” only open what you explicitly need
- Default allow outgoing traffic β€” most apps need to reach the internet
- Every open port is attack surface β€” question each one before adding

## Essential Ports
- SSH (22 or custom): Always needed for remote access β€” consider limiting to your IP only
- HTTP (80): Only if serving web traffic β€” also needed for Let's Encrypt HTTP challenge
- HTTPS (443): For production web services
- Don't open database ports (3306, 5432, 27017) to the internet β€” access via SSH tunnel or private network

## Provider Firewalls (Hetzner, DigitalOcean, AWS, etc.)
- Provider firewall applies before traffic reaches your server β€” faster, less server load
- Changes usually apply immediately β€” no reload command needed
- Stateful by default β€” allow inbound, responses automatically allowed outbound
- Apply to server groups for consistency β€” easier than per-server rules
- Provider firewall + OS firewall = defense in depth β€” use both when possible

## IP Restrictions
- Limit SSH to known IPs when possible β€” dramatically reduces attack surface
- Your home IP may change β€” use a VPN with static IP or update rules when it changes
- Allow IP ranges with CIDR notation β€” /32 is single IP, /24 is 256 IPs
- Some providers support dynamic DNS in rules β€” check before building complex solutions

## Common Services to Consider
- VPN (WireGuard: 51820/UDP, OpenVPN: 1194) β€” allows secure access without exposing other ports
- Mail (25, 465, 587) β€” only if running mail server
- DNS (53 TCP/UDP) β€” only if running DNS server
- Monitoring agents may need outbound access to specific IPs

## Docker Warning
- Docker bypasses most OS firewalls by default β€” containers expose ports regardless of UFW/iptables
- Solution: bind containers to localhost only and use reverse proxy for public access
- Or configure Docker to respect firewall rules β€” requires additional setup
- Provider-level firewalls still work β€” they block before traffic reaches Docker

## IPv6
- Firewalls often have separate IPv4 and IPv6 rules β€” configure both
- Provider firewalls may handle both together β€” check their documentation
- Attackers probe IPv6 when IPv4 is locked down β€” don't neglect it

## Debugging
- Test from outside your network β€” rules may look correct but not work
- Provider dashboards often show blocked traffic logs
- "Connection refused" = port closed properly; "Connection timeout" = firewall dropping silently
- Online port scanners verify what's actually open from the internet

## Common Mistakes
- Opening ports "temporarily" and forgetting to close them
- Opening 80/443 when no web server runs β€” unnecessary exposure
- Forgetting UDP for services that need it β€” DNS, VPN, game servers
- Assuming firewall is active β€” verify it's actually running/applied
- Only configuring IPv4 β€” leaving IPv6 wide open
- Trusting "security through obscurity" β€” non-standard ports slow attackers, don't stop them

Files in this skill

  • SKILL.md3.5 KB
  • _meta.json168 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…