ufw default deny incoming
ufw default deny incoming
Hi.
Not sure what I am missing here but I have a Debian 10 server where I am trying to use ufw for my firewall settings.
But the default rule of deny incoming is removed after I reboot my server. If I run "ufw default deny incoming" after I have rebooted, then all ports are denied except for those I have opened. But after a reboot, it seems that the default is set to accept all incoming.
What am I missing here?
Regards,
BTJ
Not sure what I am missing here but I have a Debian 10 server where I am trying to use ufw for my firewall settings.
But the default rule of deny incoming is removed after I reboot my server. If I run "ufw default deny incoming" after I have rebooted, then all ports are denied except for those I have opened. But after a reboot, it seems that the default is set to accept all incoming.
What am I missing here?
Regards,
BTJ
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
- Hallvor
- Global Moderator
- Posts: 2162
- Joined: 2009-04-16 18:35
- Location: Kristiansand, Norway
- Has thanked: 171 times
- Been thanked: 246 times
Re: ufw default deny incoming
Did you enable it?
Code: Select all
# ufw enable
# ufw default deny incoming
# ufw default allow outgoing
[HowTo] Install and configure Debian bookworm
Debian 12 | KDE Plasma | ThinkPad T440s | 4 × Intel® Core™ i7-4600U CPU @ 2.10GHz | 12 GiB RAM | Mesa Intel® HD Graphics 4400 | 1 TB SSD
Debian 12 | KDE Plasma | ThinkPad T440s | 4 × Intel® Core™ i7-4600U CPU @ 2.10GHz | 12 GiB RAM | Mesa Intel® HD Graphics 4400 | 1 TB SSD
Re: ufw default deny incoming
Yes, after boot the status says:
But the deny incoming is not working...
Code: Select all
# ufw status verbose
Status: active
Logging: off
Default: deny (incoming), allow (outgoing), disabled (routed)
New profiles: skip
To Action From
-- ------ ----
more rules
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
- dilberts_left_nut
- Administrator
- Posts: 5476
- Joined: 2009-10-05 07:54
- Location: enzed
- Has thanked: 22 times
- Been thanked: 95 times
Re: ufw default deny incoming
How do you know?bjorntj wrote:But the deny incoming is not working...
AdrianTM wrote:There's no hacker in my grandma...
Re: ufw default deny incoming
Because a port I have specifically opened from just one ip, is open for all ip's...
Running "ufw default deny incoming" after boot, fixes the firewall...
I am not a newbie in this game..
But I have never used UFW before, maybe it's just better to use iptables....
BTJ
Running "ufw default deny incoming" after boot, fixes the firewall...
I am not a newbie in this game..
data:image/s3,"s3://crabby-images/e948d/e948df2ed24ab1a82e72f7613c937ce10993b55d" alt="Cool 8)"
But I have never used UFW before, maybe it's just better to use iptables....
BTJ
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
Re: ufw default deny incoming
btw, if I compare the iptables rules after boot and after running "ufw default deny incoming", I see the following:
right after boot:
after running the deny command:
So it seems like the default rules are not applied on boot...
right after boot:
Code: Select all
hain INPUT (policy ACCEPT)
target prot opt source destination
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Code: Select all
Chain INPUT (policy DROP)
target prot opt source destination
ufw-before-logging-input all -- 0.0.0.0/0 0.0.0.0/0
ufw-before-input all -- 0.0.0.0/0 0.0.0.0/0
ufw-after-input all -- 0.0.0.0/0 0.0.0.0/0
ufw-after-logging-input all -- 0.0.0.0/0 0.0.0.0/0
ufw-reject-input all -- 0.0.0.0/0 0.0.0.0/0
ufw-track-input all -- 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy DROP)
target prot opt source destination
ufw-before-logging-forward all -- 0.0.0.0/0 0.0.0.0/0
ufw-before-forward all -- 0.0.0.0/0 0.0.0.0/0
ufw-after-forward all -- 0.0.0.0/0 0.0.0.0/0
ufw-after-logging-forward all -- 0.0.0.0/0 0.0.0.0/0
ufw-reject-forward all -- 0.0.0.0/0 0.0.0.0/0
ufw-track-forward all -- 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ufw-before-logging-output all -- 0.0.0.0/0 0.0.0.0/0
ufw-before-output all -- 0.0.0.0/0 0.0.0.0/0
ufw-after-output all -- 0.0.0.0/0 0.0.0.0/0
ufw-after-logging-output all -- 0.0.0.0/0 0.0.0.0/0
ufw-reject-output all -- 0.0.0.0/0 0.0.0.0/0
ufw-track-output all -- 0.0.0.0/0 0.0.0.0/0
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
-
- Section Moderator
- Posts: 1267
- Joined: 2014-06-30 11:42
- Has thanked: 132 times
- Been thanked: 64 times
Re: ufw default deny incoming
I don't have experience with ufw (why don't you use nftables?), but maybe doing a "systemctl status ufw" after boot will tell you if it is enabled and whether it started OK or not.
If not enabled, do "systemctl enable ufw" (assuming there's a ufw.service).
If not enabled, do "systemctl enable ufw" (assuming there's a ufw.service).
Re: ufw default deny incoming
Thx, but as I said, ufw is enabled and running after boot, it's just that the default rules are not applied....
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
-
- Section Moderator
- Posts: 1267
- Joined: 2014-06-30 11:42
- Has thanked: 132 times
- Been thanked: 64 times
Re: ufw default deny incoming
OK, can you check if you have /etc/ufw/user.rules and/or /etc/ufw/user6.rules, and if they have the content you'd expect (that's where your rules are supposed to be saved).
I imagine there's no need to ask if you have *another* firewall starting/configuring at boot (nftables, iptables-persistent, etc.) which might be cleaning up what ufw has done while initializing?
I imagine there's no need to ask if you have *another* firewall starting/configuring at boot (nftables, iptables-persistent, etc.) which might be cleaning up what ufw has done while initializing?
Re: ufw default deny incoming
No, I don't... And yes, those files exists and looks fine..
But I have been looking at nftables now and I think I will be swithing to nftables instead... Thx..data:image/s3,"s3://crabby-images/24bdf/24bdf1c045f44ae8ce3148a97c9c500649319395" alt="Smile :)"
BTJ
But I have been looking at nftables now and I think I will be swithing to nftables instead... Thx..
data:image/s3,"s3://crabby-images/24bdf/24bdf1c045f44ae8ce3148a97c9c500649319395" alt="Smile :)"
BTJ
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
- Ardouos
- Posts: 1080
- Joined: 2013-11-03 00:30
- Location: Elicoor II
- Has thanked: 1 time
- Been thanked: 4 times
Re: ufw default deny incoming
+1 for nftables.
I switched to it after I installed Buster and I was surprised with how simple it was. You can manage it by using commands or directly editing the text file (just be careful with the correct formatting). The main disadvantage as of today is that there is less documentation on it. But that may change due to time.
The wiki if you need to refer to it. Otherwise there are guides online which people have made.
https://wiki.nftables.org/wiki-nftables ... /Main_Page
The link below will drop all incoming whilst allowing connections that your computer has made, as well as loopback.
Simple rules for a desktop:
https://wiki.nftables.org/wiki-nftables ... orkstation
I switched to it after I installed Buster and I was surprised with how simple it was. You can manage it by using commands or directly editing the text file (just be careful with the correct formatting). The main disadvantage as of today is that there is less documentation on it. But that may change due to time.
The wiki if you need to refer to it. Otherwise there are guides online which people have made.
https://wiki.nftables.org/wiki-nftables ... /Main_Page
The link below will drop all incoming whilst allowing connections that your computer has made, as well as loopback.
Simple rules for a desktop:
https://wiki.nftables.org/wiki-nftables ... orkstation
There is only one Debian | Do not break Debian | Stability and Debian | Backports
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀
Re: ufw default deny incoming
Yes, got my rules set up and seems to be working as it should now...
Thx..data:image/s3,"s3://crabby-images/24bdf/24bdf1c045f44ae8ce3148a97c9c500649319395" alt="Smile :)"
Thx..
data:image/s3,"s3://crabby-images/24bdf/24bdf1c045f44ae8ce3148a97c9c500649319395" alt="Smile :)"
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
-
- Section Moderator
- Posts: 1267
- Joined: 2014-06-30 11:42
- Has thanked: 132 times
- Been thanked: 64 times
Re: ufw default deny incoming
Good to hear!bjorntj wrote:Yes, got my rules set up and seems to be working as it should now...
Thx.. :)
The only problem I have with nftables, which I use everywhere (desktop and server) is with docker, as it still depends (in the debian sense) on iptables. You can avoid it by setting "iptables: false" in the daemon.json config, but then you have to set your forwarding rules, etc. by yourself..
Re: ufw default deny incoming
ok, good to know... data:image/s3,"s3://crabby-images/24bdf/24bdf1c045f44ae8ce3148a97c9c500649319395" alt="Smile :)"
data:image/s3,"s3://crabby-images/24bdf/24bdf1c045f44ae8ce3148a97c9c500649319395" alt="Smile :)"
Someone wrote:
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"
"I understand that if you play a Windows CD backwards you hear strange Satanic messages"
To which someone replied:
"It's even worse than that; play it forwards and it installs Windows"