Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add recommended hetzner firewall documentation #147

Closed
rbo opened this issue Dec 9, 2020 · 2 comments
Closed

Add recommended hetzner firewall documentation #147

rbo opened this issue Dec 9, 2020 · 2 comments
Labels
documentation Improvements or additions to documentation

Comments

@rbo
Copy link
Contributor

rbo commented Dec 9, 2020

No description provided.

@rbo rbo added the documentation Improvements or additions to documentation label Dec 9, 2020
@ikke-t
Copy link

ikke-t commented Dec 9, 2020

My personal experience as a comment here. There are two options for the firewall. 1) Hetzner offers GUI for managing firewall in front of your server, 2) use firewalld on your server, if it's CentOS/RHEL/etc.

I personally block ports I never want open (RPC bind + portmapper) in Hetzner firewall just in case, and leave anything else open. Then I do set more fine grained rules on the Linux itself. E.g. all kinds of port mappings to VMs etc.

Just to say, I find it good to have it in two layers like that. So if you don't do anything weird in your linux, you don't even need to block anything there, just forward the service ports for VMs. Result is that you have only ssh open hopefully in some high port on host, and things like OCP API 6443 & 80 & 443 being forwarded to OCP VMs.. I also run tower, and some VM direct ssh port openings on the host on high ports, and find this as a good setup for me.

@rbo
Copy link
Contributor Author

rbo commented Dec 23, 2020

Fixed in devel branch, will be merged into master via PR #159

@rbo rbo closed this as completed Dec 23, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants