4 ms·
In production never ever use ufw or firewalld. Learn a few rules in iptables and that all or create a simple script. The problem with ufw or firewalld(not only
by dddddddddddd 5y ago
In production never ever use ufw or firewalld. Learn a few rules in iptables and that all or create a simple script.
The problem with ufw or firewalld(not only with this 2) they add so many rules in iptables, that a human can do very easy mistakes or the rules are not on your control.
- mercora 5y ago... even if you handcraft your rules, docker will still, by default, add its own rulesets... ive helped people bitten by this on occasions mostly because it changes the default forward policy to drop... its also really hard to manage this concurrently... i.e if you need to reload your own rulesets you need to tell docker to reinsert its own afterward or make sure you run after docker did its thing... oh and of course you should not just save your current rulesets either in order to leave the docker rulesets out of yours and still make sure you know how their rules will affect yours then... its horrible...