Firewall.
Included. Review first, then apply.
- Inbound and outbound
- IPv6 and IPv4
Rules, in order.
Ordered rules
The first rule that matches decides.
Inbound and outbound
Other inbound traffic: dropped.
Allow, drop, reject
Per rule, with logging on or off.
Source and destination
Address, range, address list or private network.
One policy, many machines
Apply it to machines in the project.
Default policy
For every new machine.
The diff first.
Changes stay a draft until you apply them.
- Every change shown, a new order too
- Takes effect within about 10 seconds
- A colleague got there first? You see their changes first
Will it get through?
Fill in protocol, port and source; the rule that decides is highlighted.
- Unapplied changes too
- Log per machine: time, verdict, port, from and to
- Which rule decided
Set it once.
Presets
| Preset | Protocol and port |
|---|---|
| SSH | TCP 22 |
| HTTP | TCP 80 |
| HTTPS | TCP 443 |
| DNS | UDP and TCP 53 |
| Ping | ICMP and ICMPv6 echo |
| RDP | TCP 3389 |
| MySQL | TCP 3306 |
| PostgreSQL | TCP 5432 |
| SMTP | TCP 25 |
| WireGuard | UDP 51820 |
| Custom rule | TCP or UDP: port, range or list |
Address list: Office¹
| Address or network | Comment |
|---|---|
| 198.51.100.0/24 | Office |
| 2001:db8:ff::/48 | Office, IPv6 |
| 203.0.113.7 | VPN |
| ! 198.51.100.13 | Exception: guests |
- ¹An example. A list applies in every rule of the project that uses it.
Always on.
Also when a machine’s firewall is off.
- Anti-spoofing
- MAC filter
- RA and DHCP guard
- Outbound mail (port 25) closed¹
- ¹Closed for new accounts. Opened on request.
About the firewall.
What does the firewall cost?
Nothing. The axnet firewall is included.
What is allowed by default?
Inbound, only what your rules allow. Outbound, everything except mail on port 25.
How fast does a change take effect?
Within about 10 seconds after you apply it.
Can I send mail over port 25?
Port 25 is closed for new accounts. Ask us, and we open it.
What if a colleague edits at the same time?
You see their changes first and choose: keep both, theirs or yours.
And when a machine’s firewall is off?
Then all traffic to that machine is allowed. Anti-spoofing, MAC filter and RA and DHCP guard stay on.