Skip to content

Firewall.

Included. Review first, then apply.

  • Inbound and outbound
  • IPv6 and IPv4
Console: the policy Web servers with two inbound rules, HTTP from anywhere and SSH from the address list Office; all other inbound traffic dropped.

Rules, in order.

  • Ordered rules

    The first rule that matches decides.

  • Inbound and outbound

    Other inbound traffic: dropped.

  • Allow, drop, reject

    Per rule, with logging on or off.

  • Source and destination

    Address, range, address list or private network.

  • One policy, many machines

    Apply it to machines in the project.

  • Default policy

    For every new machine.

The diff first.

Changes stay a draft until you apply them.

  • Every change shown, a new order too
  • Takes effect within about 10 seconds
  • A colleague got there first? You see their changes first
Console: reviewing changes to Web servers. Rule 3, allow TCP 443 from anywhere to this machine, reaches web-01 and web-02.

Will it get through?

Fill in protocol, port and source; the rule that decides is highlighted.

  • Unapplied changes too
  • Log per machine: time, verdict, port, from and to
  • Which rule decided
Console: web-02’s Firewall tab. TCP from 198.51.100.7 to port 443 is allowed by rule 3 of Web servers; the recent firewall log below.

Set it once.

Presets

Presets: protocol and port
PresetProtocol and port
SSHTCP 22
HTTPTCP 80
HTTPSTCP 443
DNSUDP and TCP 53
PingICMP and ICMPv6 echo
RDPTCP 3389
MySQLTCP 3306
PostgreSQLTCP 5432
SMTPTCP 25
WireGuardUDP 51820
Custom ruleTCP or UDP: port, range or list

Address list: Office¹

An example address list
Address or networkComment
198.51.100.0/24Office
2001:db8:ff::/48Office, IPv6
203.0.113.7VPN
! 198.51.100.13Exception: guests
  1. ¹An example. A list applies in every rule of the project that uses it.

Always on.

Also when a machine’s firewall is off.

  • Anti-spoofing
  • MAC filter
  • RA and DHCP guard
  • Outbound mail (port 25) closed¹
  1. ¹Closed for new accounts. Opened on request.
Request port 25
Console: HTTPS applied to Web servers. Protected by axnet: anti-spoofing, MAC filter, RA and DHCP guard and outbound mail (port 25), always on.

About the firewall.

All questions
What does the firewall cost?

Nothing. The axnet firewall is included.

What is allowed by default?

Inbound, only what your rules allow. Outbound, everything except mail on port 25.

How fast does a change take effect?

Within about 10 seconds after you apply it.

Can I send mail over port 25?

Port 25 is closed for new accounts. Ask us, and we open it.

What if a colleague edits at the same time?

You see their changes first and choose: keep both, theirs or yours.

And when a machine’s firewall is off?

Then all traffic to that machine is allowed. Anti-spoofing, MAC filter and RA and DHCP guard stay on.