• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Question Seeking help with firewall rules

dsherron

New Pleskian
Server operating system version
Ubuntu 20.04.5 LTS
Plesk version and microupdate number
Plesk Obsidian v18.0.48_build1800221104.03
Hi all,

I am fairly new to Plesk.

My question is not how to configure the firewall rules but what (and why) firewall rules to configure. I have searched and searched and all I find is articles about the how but not the what/why.

I would really appreciate pointers to useful resources, tutorials, books, anything (but not procedural/mechanical--I get that).

Thanks!
 
Utilizing the default rules is best as a starting point as it will give access to only the ports needed from the internet. As for why you should use a firewall, it's to protect you from unauthorized access through a unknown port that might have an exploit. Your home router, for example, is also a firewall.
 
The default rules, according to an email I received from AWS, is vulnerable to malicious actors. Plus, it looks wide open to me and I have not touched it.
 
If you're using AWS, you will have additional security configuration on the VPC anyways so utilizing the default policies is fine in your case and just open the bare minimal on the VPC network security group (80, 443, 8443, 8447 (is is for plesk update page), 25, 254, 993).
 
Back
Top