<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Suggest a good basic setting for firewall?]]></title><description><![CDATA[<p dir="auto">Hello all!<br />
I was just watching a video on youtube about allowing / preventing port 80 / 443 as examples of WAN_IN rules</p>
<p dir="auto">So I began tho think, should I set rules to allow ONLY port 80 / 443/ and my ssh?</p>
<p dir="auto">Would that reduce intrusions and flyby malware / etc attacks?<br />
Or, would it just be good business to only allow ports 80 / 443 / for folks who are average web surfers?</p>
<p dir="auto">Thanks for providing any comments</p>
]]></description><link>https://forum.netgate.com/topic/113918/suggest-a-good-basic-setting-for-firewall</link><generator>RSS for Node</generator><lastBuildDate>Tue, 08 Sep 2026 13:34:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/113918.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 02 Apr 2017 01:52:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Suggest a good basic setting for firewall? on Sun, 02 Apr 2017 17:17:34 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for a great solution!  My next step is to read all I can on whitelisting</p>
<p dir="auto">I am experimenting with the Ubiquiti Edgerouter X and Lite as well as PfSense.  I want to provide the best protection without handicapping use of staff in a number of offices ranging from 1 staff on site to 12-20 on site.</p>
<p dir="auto">Once I get enough "live" use from each, I  can present to the management and recommend how to proceed.  It appears I may use both depending on the amount of staff at the location.</p>
<p dir="auto">I ordered 3 SG2440 appliances, and have built another 6 pfsense boxes out of Dell Optiplex 390/990/9020 computers.  They all work great.</p>
<p dir="auto">The ubiquiti routers are real work horses.  So after I can see which is easier to manage at really remote locations, I can dump the crappy  belkin/dlink WalMart routers that are in place now</p>
<p dir="auto">Again, thanks for the response.  It will help me tremendously</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/pfbasic">@<bdi>pfBasic</bdi></a>:</p>
<blockquote>
<p dir="auto">you're talking generally about white listing your LAN.</p>
<p dir="auto">The advantage is you have more control over traffic leaving your LAN.</p>
<p dir="auto">If you are using an <em>allow any any any…</em> rule on LAN then obviously anything on your LAN that wants to get out can go anywhere it wants.</p>
<p dir="auto">If you have no rules on LAN then no traffic is getting out.</p>
<p dir="auto">If you remove the <em>allow any any any…</em> rule then you can write rules and aliases to specify exactly what gets out of your LAN.</p>
<p dir="auto">I happen to whitelist my LAN, but I personally did it as an educational exercise to learn wtf firewall rules are and how they work.</p>
<p dir="auto">While whitelisting your LAN theoretically (and to some extent really does) lock down your network, it is just one more measure towards security and won't make you safe by itself. I would expect a real threat or malware to be able to exit a network on common ports, but maybe not.</p>
<p dir="auto">With that being said, I still recommend it! It's really not difficult to set up, and just by setting it up you understand exactly what is exiting your LAN.</p>
<p dir="auto">You will need more than 80/443 though (probably). You likely also want some ports for email, SSH, DHCP, DNS, NTP, and the high ports.<br />
A few aliases, some quick googling and anyone can set up whitelisting.</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/690705</link><guid isPermaLink="true">https://forum.netgate.com/post/690705</guid><dc:creator><![CDATA[detox]]></dc:creator><pubDate>Sun, 02 Apr 2017 17:17:34 GMT</pubDate></item><item><title><![CDATA[Reply to Suggest a good basic setting for firewall? on Sun, 02 Apr 2017 03:20:26 GMT]]></title><description><![CDATA[<p dir="auto">you're talking generally about white listing your LAN.</p>
<p dir="auto">The advantage is you have more control over traffic leaving your LAN.</p>
<p dir="auto">If you are using an <em>allow any any any…</em> rule on LAN then obviously anything on your LAN that wants to get out can go anywhere it wants.</p>
<p dir="auto">If you have no rules on LAN then no traffic is getting out.</p>
<p dir="auto">If you remove the <em>allow any any any…</em> rule then you can write rules and aliases to specify exactly what gets out of your LAN.</p>
<p dir="auto">I happen to whitelist my LAN, but I personally did it as an educational exercise to learn wtf firewall rules are and how they work.</p>
<p dir="auto">While whitelisting your LAN theoretically (and to some extent really does) lock down your network, it is just one more measure towards security and won't make you safe by itself. I would expect a real threat or malware to be able to exit a network on common ports, but maybe not.</p>
<p dir="auto">With that being said, I still recommend it! It's really not difficult to set up, and just by setting it up you understand exactly what is exiting your LAN.</p>
<p dir="auto">You will need more than 80/443 though (probably). You likely also want some ports for email, SSH, DHCP, DNS, NTP, and the high ports.<br />
A few aliases, some quick googling and anyone can set up whitelisting.</p>
]]></description><link>https://forum.netgate.com/post/690631</link><guid isPermaLink="true">https://forum.netgate.com/post/690631</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Sun, 02 Apr 2017 03:20:26 GMT</pubDate></item></channel></rss>