Firewall

nftables managed from the panel: ports, allowed and blocked addresses, CSF import and brute-force bans.

Used by
Admin
Plan
Free
Status
Available
Category
Monitoring and security

What it is

The firewall seeds the ports of the services the installer put in place and lets you add or close others per protocol and range. Bans expire in the kernel, so no daemon has to lift them. A CSF configuration can be imported so existing tuning is kept.

What it is for

Locking a node down without leaving the panel.

Limits

SSH and the two panel ports can never be closed from the panel. It is not switched on silently on a node that is already serving. Repeated failed panel logins from one address are banned at the firewall.