_CORE
AI & Agentic Systems Core Information Systems Cloud & Platform Engineering Data Platform & Integration Security & Compliance QA, Testing & Observability IoT, Automation & Robotics Mobile & Digital Banking & Finance Insurance Public Administration Defense & Security Healthcare Energy & Utilities Telco & Media Manufacturing Logistics & E-commerce Retail & Loyalty
References Technologies Blog Know-how Tools
About Collaboration Careers
CS EN
Let's talk

Firewall pravidla — best practices

14. 08. 2025 1 min read intermediate

Firewall je první linie obrany. Default deny, minimální otevřené porty, logování.

iptables

iptables -P INPUT DROP iptables -P FORWARD DROP iptables -A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT iptables -A INPUT -i lo -j ACCEPT iptables -A INPUT -p tcp –dport 22 -s 10.0.100.0/24 -j ACCEPT iptables -A INPUT -p tcp –dport 443 -j ACCEPT iptables -A INPUT -j LOG –log-prefix “DROP: ” iptables -A INPUT -j DROP

nftables

table inet filter { chain input { type filter hook input priority 0; policy drop; ct state established,related accept tcp dport { 80, 443 } accept tcp dport 22 ip saddr 10.0.100.0/24 accept } }

Key Takeaway

Default deny, minimální porty, logování zamítnutých pokusů.

securityfirewallnetworkiptables
Share:

CORE SYSTEMS tým

Stavíme core systémy a AI agenty, které drží provoz. 15 let zkušeností s enterprise IT.