this post was submitted on 24 Mar 2025
96 points (95.3% liked)

Selfhosted

45119 readers
743 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I've been running my server without a firewall for quite some time now, I have a piped instance and snikket running on it. I've been meaning to get UFW on it but I've been too lazy to do so. Is it a necessary thing that I need to have or it's a huge security vulnerability? I can only SSH my server from only my local network and must use a VPN if I wanna SSH in outside so I'd say my server's pretty secure but not the furthest I could take it. Opinions please?

(page 2) 14 comments
sorted by: hot top controversial new old
[–] Flax_vert@feddit.uk 1 points 4 days ago

Just make sure you're using public key authentication and you're good

[–] ShortN0te@lemmy.ml -4 points 5 days ago* (last edited 5 days ago)

You do not even need a port based firewall when the server is open on the internet.

When you configure the software to not have unnecessary open ports over the internet connected interface then a port based firewall is providing zero additional security.

A port based firewall has the benefit that you can lock everything down to the few ports you actually need, and do not have to worry about misconfigured software.

For example, something like docker circumvents ufw anyway. And i know ppl that had open ports even tho they had ufw running.

load more comments
view more: ‹ prev next ›