Compare commits
6 Commits
297cf76772
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| 1a9df9e12e | |||
| b643441453 | |||
| 5e3c9cbc29 | |||
| 379484de22 | |||
| 0205a08a0c | |||
| 4e4aea28ec |
@@ -2,8 +2,8 @@
|
||||
title: Firewall Linux
|
||||
description: Firewall Konfiguration unter Linux
|
||||
published: true
|
||||
date: 2026-03-16T00:13:44.032Z
|
||||
tags: firewall, linux
|
||||
date: 2026-03-16T00:26:49.413Z
|
||||
tags: firewall, linux, fail2ban, ufw, brutforce
|
||||
editor: markdown
|
||||
dateCreated: 2026-03-15T23:56:44.726Z
|
||||
---
|
||||
@@ -39,3 +39,32 @@ Mit diesem Befehl schaltet man die Firewall ein:
|
||||
```bash
|
||||
sudo ufw enable
|
||||
```
|
||||
Die Maschine neustarten und danach prüfen:
|
||||
```bash
|
||||
sudo ufw status numbered
|
||||
```
|
||||
## Empfehlungen Firewall Einstellungen
|
||||
1) Default Policies setzen (sehr wichtig)
|
||||
```bash
|
||||
sudo ufw default deny incoming
|
||||
sudo ufw default allow outgoing
|
||||
```
|
||||
2) SSH Bruteforce Schutz
|
||||
```bash
|
||||
ufw limit 22/tcp
|
||||
```
|
||||
3) Das blockiert automatisch IPs bei Login-Angriffen (fail2ban)
|
||||
```bash
|
||||
apt install fail2ban
|
||||
```
|
||||
Damit kann man überprüfen, ob fail2ban läuft:
|
||||
```bash
|
||||
systemctl status fail2ban
|
||||
```
|
||||
|
||||
4) Logging vom default low zu medium erhöhen
|
||||
Die Logfiles findet man allgemein hier: `sudo less /var/log/ufw.log`
|
||||
```bash
|
||||
sudo ufw logging medium
|
||||
```
|
||||
|
||||
|
||||
Reference in New Issue
Block a user