r/linuxadmin • u/worldarkplace • 12d ago
Firewall rule
Is the ideal rule to deny all and only allow everything from your local LAN(IPv4) and link-local(IPv6) network?
For my use case my devices use DHCP and I need that different IPs from my network to connect to different services.
I know the best is to only allow the ports you will use, but this can vary in my case.
What do you think/do?
8
Upvotes
1
u/michaelpaoli 12d ago
Not generally, and you may quite break things that way. Maybe first start by figuring out what your objectives are. If you want the utmost in fierwalls, get rid of all manner of networking - entirely remove that attack surface, and then you're highly well protected from those attacks.