firewall-config

Firewall Configuration

Safety Notice

This listing is imported from skills.sh public index metadata. Review upstream SKILL.md and repository scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "firewall-config" with this command: npx skills add bagelhole/devops-security-agent-skills/bagelhole-devops-security-agent-skills-firewall-config

Firewall Configuration

Configure host-based and cloud firewalls for network security.

iptables

Default policies

iptables -P INPUT DROP iptables -P FORWARD DROP iptables -P OUTPUT ACCEPT

Allow established connections

iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

Allow loopback

iptables -A INPUT -i lo -j ACCEPT

Allow SSH

iptables -A INPUT -p tcp --dport 22 -j ACCEPT

Allow HTTP/HTTPS

iptables -A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT

Save rules

iptables-save > /etc/iptables/rules.v4

nftables

#!/usr/sbin/nft -f flush ruleset

table inet filter { chain input { type filter hook input priority 0; policy drop; ct state established,related accept iif "lo" accept tcp dport { 22, 80, 443 } accept }

chain forward { type filter hook forward priority 0; policy drop; }

chain output { type filter hook output priority 0; policy accept; } }

AWS Security Groups

aws ec2 create-security-group --group-name web-sg --description "Web server SG"

aws ec2 authorize-security-group-ingress
--group-name web-sg
--protocol tcp --port 443
--cidr 0.0.0.0/0

Best Practices

  • Default deny policy

  • Minimal rule sets

  • Regular rule audits

  • Log denied traffic

  • Document all rules

Related Skills

  • linux-hardening - System security

  • aws-vpc - AWS networking

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

linux-administration

No summary provided by upstream source.

Repository SourceNeeds Review
Security

linux-hardening

No summary provided by upstream source.

Repository SourceNeeds Review
Security

sops-encryption

No summary provided by upstream source.

Repository SourceNeeds Review
Security

vpn-setup

No summary provided by upstream source.

Repository SourceNeeds Review