i installed ufw (ubuntu firewall) on my linux server and set up simple rules: http (80), https (443), ssh (22) open; everything else closed. but another server admin sent me an email section saying i should open ports like smtp (25), imap (143), dns (53). but my server doesn't have mail services, why would i need to open them?
is opening port 22 (ssh) to the internet enough for security? should i change the port number to protect against brute force attacks?
just opening and closing ports isn't enough. besides the firewall, do i need to set up other things on the network side? there are other servers inside (mysql database server, cache server), do i need to protect the traffic between them too?