• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Firewall secure rules

Pascal_Netenvie

Regular Pleskian
Hi,
I try to secure servers as much as possible.

As our servers never host this services : PostgreSQL, mail boxes, DNS rules, windows file sharing and don't allow/need external connection to databases,
is it really ok to set all these rules ?

rule-deny.png
POP3 (mail retrieval) server Deny incoming from all
rule-deny.png
IMAP (mail retrieval) server Deny incoming from all
rule-deny.png
Mail password change service Deny incoming from all
rule-deny.png
PostgreSQL server Deny incoming from all
rule-deny.png
Tomcat administrative interface Deny incoming from all
rule-deny.png
Samba (file sharing in Windows networks) Deny incoming from all
rule-deny.png
Domain name server Deny incoming from all

MySQL server Allow incoming from 127.0.0.1

Also is there any other services we can deny connect to ?
For example "Plesk VPN" (What is it for ?) or "Customer & Business Manager payment gateways" (We use plesk only to host our websites, no resell) ?

Thx for your answer.
 
Last edited:
Hey,
Thx for the link.

I know this but my question started with :
As our servers never host PostgreSQL, mail boxes, DNS rules, windows file sharing and don't allow/need external connection to databases ...

So do you think this is ok ?

And also these points :
"Plesk VPN" (What is it for ?)
"Customer & Business Manager payment gateways" (We use plesk only to host our websites, no resell) ?
 
Hi Pascal_Netenvie,

to point: Plesk VPN
I hope that you don't get this wrong, but when you have to ask "What is it for ?", then you definetly don't need it on your server and shouldn't open ports for it and when you didn't open ports for it, then you don't have to customize firewall rules for this port(s) as well.

to point: Customer & Business Manager payment gateways
And again here as well: If you don't use a special service on your server, you will not open ports for it, which again makes customizing firewall rules useless.
 
when you have to ask "What is it for ?", then you definetly don't need it on your server

Yes generally but i prefer to validate it cause sometimes you think a service is unused but it is in back.
And as we can't know everything it is always better to ask ...

If you don't use a special service on your server, you will not open ports for it, which again makes customizing firewall rules useless.

Ok. No cases of demon running for nothing and ports let open ?

Thanks.
 
Back
Top