Installs into .claude/skills of the current project.
Are you the author of Firewall?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/clawic-firewall)
---
name: Firewall
slug: firewall
version: 1.0.0
description: Configure firewalls on servers and cloud providers with security best practices.
homepage: https://clawic.com/skills/firewall
metadata:
clawdbot:
emoji: π‘οΈ
os:
- linux
- darwin
- win32
displayName: Firewall
---
# Firewall Rules
## Critical First Steps
- Allow SSH/remote access before enabling any firewall β enabling first locks you out
- Test access in a second session before closing the first β verify the rule actually works
- Know how to access provider console β it's the only way back if locked out
## Default Stance
- Default deny all incoming traffic β only open what you explicitly need
- Default allow outgoing traffic β most apps need to reach the internet
- Every open port is attack surface β question each one before adding
## Essential Ports
- SSH (22 or custom): Always needed for remote access β consider limiting to your IP only
- HTTP (80): Only if serving web traffic β also needed for Let's Encrypt HTTP challenge
- HTTPS (443): For production web services
- Don't open database ports (3306, 5432, 27017) to the internet β access via SSH tunnel or private network
## Provider Firewalls (Hetzner, DigitalOcean, AWS, etc.)
- Provider firewall applies before traffic reaches your server β faster, less server load
- Changes usually apply immediately β no reload command needed
- Stateful by default β allow inbound, responses automatically allowed outbound
- Apply to server groups for consistency β easier than per-server rules
- Provider firewall + OS firewall = defense in depth β use both when possible
## IP Restrictions
- Limit SSH to known IPs when possible β dramatically reduces attack surface
- Your home IP may change β use a VPN with static IP or update rules when it changes
- Allow IP ranges with CIDR notation β /32 is single IP, /24 is 256 IPs
- Some providers support dynamic DNS in rules β check before building complex solutions
## Common Services to Consider
- VPN (WireGuard: 51820/UDP, OpenVPN: 1194) β allows secure access without exposing other ports
- Mail (25, 465, 587) β only if running mail server
- DNS (53 TCP/UDP) β only if running DNS server
- Monitoring agents may need outbound access to specific IPs
## Docker Warning
- Docker bypasses most OS firewalls by default β containers expose ports regardless of UFW/iptables
- Solution: bind containers to localhost only and use reverse proxy for public access
- Or configure Docker to respect firewall rules β requires additional setup
- Provider-level firewalls still work β they block before traffic reaches Docker
## IPv6
- Firewalls often have separate IPv4 and IPv6 rules β configure both
- Provider firewalls may handle both together β check their documentation
- Attackers probe IPv6 when IPv4 is locked down β don't neglect it
## Debugging
- Test from outside your network β rules may look correct but not work
- Provider dashboards often show blocked traffic logs
- "Connection refused" = port closed properly; "Connection timeout" = firewall dropping silently
- Online port scanners verify what's actually open from the internet
## Common Mistakes
- Opening ports "temporarily" and forgetting to close them
- Opening 80/443 when no web server runs β unnecessary exposure
- Forgetting UDP for services that need it β DNS, VPN, game servers
- Assuming firewall is active β verify it's actually running/applied
- Only configuring IPv4 β leaving IPv6 wide open
- Trusting "security through obscurity" β non-standard ports slow attackers, don't stop them