forumNew topic

i set up firewall rules but are they all correct? ports 80, 443, 22 — what else should i close?

IIrmak B***MemberCommunity member
Joined
Jan 2025
Message
304
#1

i installed ufw (ubuntu firewall) on my linux server and set up simple rules: http (80), https (443), ssh (22) open; everything else closed. but another server admin sent me an email section saying i should open ports like smtp (25), imap (143), dns (53). but my server doesn't have mail services, why would i need to open them?

is opening port 22 (ssh) to the internet enough for security? should i change the port number to protect against brute force attacks?

just opening and closing ports isn't enough. besides the firewall, do i need to set up other things on the network side? there are other servers inside (mysql database server, cache server), do i need to protect the traffic between them too?

MMurat G***Member
Job title
Purchasing manager
Sector
Sports and fitness
Organization type
20-person company
Joined
Apr 2023
Message
2
Most Helpful#2

firewall rules should be set with the 'principle of least privilege' — only necessary ports should be open. for the web server: 80 (http), 443 (https) to external, 22 (ssh) to ip whitelist. smtp/imap should stay closed if not needed. other rules: 1) change ssh port (2222 instead of 22), install fail2ban (brute force protection), 2) internal network (database, cache): firewall rule allowing access only from web server's ip (bidirectional), 3) icmp (ping) can be disabled (prevent port scanning), 4) udp outbound to all ports? no, dns (53) only to resolver, 5) rate limiting (ddos mitigation), 6) general best practice: default drop on external interface, whitelist only; internal interface trusted network is secure. for ufw: 'ufw default deny incoming, allow outgoing, limit 22'. never expose the internal database port (3306 mysql) to external.

VVildan Ö***Member
Job title
Secretary
Sector
Retail
Organization type
family business
Joined
Dec 2024
Message
66
#3

dont keep ssh port 22 open, change the port to 2222 etc. but still install fail2ban. if theres no mail, dont open smtp/imap at all.. then just keep 80 443 2222 open close the rest...

ZZafer A***Member
Job title
Secretary
Sector
Jewelry
Organization type
20-person company
Joined
Nov 2024
Message
142
#4

ufw commands: ufw default deny incoming, ufw allow 80/tcp, ufw allow 443/tcp, ufw limit 2222/tcp (rate limiting ssh), ufw deny 3306/tcp (block mysql external). check: ufw status numbered. enable logging: ufw logging on, level medium. ssh config (/etc/ssh/sshd_config): port 2222, permitrootlogin no, pubkeyauthentication yes, passwordauthentication no (key-based). restart: systemctl restart sshd. internal communication: iptables rules or security groups (cloud provider level).

FFiliz D***Expert
Job title
Customer service representative
Sector
Logistics
Organization type
cooperative
Joined
Jun 2023
Message
170
#5

simplest setup: close port 22 from the internet only open it from the office ip... or change the port make it 2222. never open mysql port 3306 only localhost. like http https are normal, don't open anything else. that's it get the simple stuff done.

EEsra I***MemberCommunity member
Joined
Dec 2023
Message
214
#6

firewall tiers: perimeter (isp level), network (router firewall), host (host-based firewall). for web server: host firewall (ufw) + cloud security group (if cloud). ssh access: bastion host behind vpn, or ip whitelist. database access: internal network only, never external. logging for all rejected packets — siem integration is ideal. rate limiting ssh + tcp syn flood protection.

NNazlı K***MemberCommunity member
Joined
Apr 2024
Message
104
#7

port 22 open = inviting hackers 😂 change the port install fail2ban done... anyway mail ports? if not needed close them, why would you open them...

OOsman K***Expert
Job title
Software developer
Sector
Education
Organization type
two-branch business
Joined
Dec 2023
Message
23
#8

You're right. Payment information changes are never verified through the channel they came from.

If it's your first time, start small; scaling comes later. Of course, it varies if your situation is different.

VVeli D***Member
Job title
Network Administrator
Sector
Education
Organization type
two-branch business
Joined
May 2022
Message
107

Doki · Infrastructure migration · 2023

#9

to get into the details: Processes without records never improve because you don't know what to fix.

good luck with that.

NNazlı A***MemberCommunity member
Joined
Oct 2025
Message
58
#10

i went through the same thing.

TTülay Y***Member
Job title
Production planning
Sector
Automotive aftermarket
Organization type
early-stage startup
Joined
Jan 2025
Message
384
#11

I partly agree, partly disagree. When you try to change everything at once, nothing settles.

Everything goes well for the first three months; problems arise in the fourth. If you post the result here, it will help others too.

KKader A***Member
Job title
Operations manager
Sector
Law
Organization type
cooperative
Joined
Apr 2025
Message
46
#12

we experienced almost the exact same thing last year. i mean the biggest time-waster for us was not knowing who had the final say.

if permission and scope aren't in writing, don't start that test... of course, it varies if your situation is different.

LLale U***ExpertCommunity member
Joined
Aug 2025
Message
2
#13

I agree. Security isn't absolute; it's about making attacks not worth the effort.

Of course, it varies if your situation is different.

FFeyza Y***Expert
Job title
Field sales representative
Sector
IT services
Organization type
medium-sized business
Joined
Jun 2024
Message
281
#14

I went through the same thing. If it's your first time, start small; scaling comes later.

If I were you, Id go this route.

OOrhan E***Member
Job title
Export manager
Sector
Law
Organization type
chain store
Joined
Dec 2025
Message
91

Doki · Vulnerability scanning · 2023

#15

We've heard this a lot, but it never happened like that for us. Payment information changes are never verified through the channel they came from.

Most incidents start with a leaked password, not a vulnerability. If I were you, I'd go this route.

KKoray T***Member
Job title
Regional Manager
Sector
Construction
Organization type
sole proprietorship
Joined
Dec 2023
Message
103
#16

Noted, thanks.

BBora A***Member
Job title
Call center representative
Sector
Livestock
Organization type
20-person company
Joined
Apr 2023
Message
301
#17

Ive been down this road let me tell you. If 2FA is on a stolen password alone is useless.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection. If I were you, I'd go this route.

EEmre D***Member
Job title
Marketing manager
Sector
Real estate
Organization type
workshop
Joined
Jan 2025
Message
340
#18

Let me summarize what's been said so far. The biggest time-waster for us was not knowing who had the final say.

An untested backup is not a backup. Of course, it varies if your situation is different.

DDeniz A***ExpertCommunity member
Joined
Aug 2025
Message
164
#19

I'll try it.

EEfe A***Member
Job title
System support specialist
Sector
Software
Organization type
8-person team
Joined
Jul 2022
Message
136

Doki · Infrastructure migration · 2025

#20

I've been down this road, let me tell you. Taking notes for two weeks yields better results than a six-month estimate.

Processes without records never improve, because you don't know what to fix. I'm also curious if anyone does it differently.

Reply