lundi 26 janvier 2015

What's the diff between blocking a port with a firewall and not starting a service on that port in the first place?



I was considering setting up a software firewall (pf) on my web server and did some research on them. Were I to do it, it'd involve basically blocking connections to all ports except 80, 443, and the non-standard port I'm using for SSH connections.


But seeing as how my server already only has services running on those ports anyway, would it just be pointless? I don't really have a need right now to region-block IPs or anything complex like that.


In simple words that someone with a not-so-complete understanding of IP networking can understand, would it still be useful for me to configure a firewall in this way? How, functionally, is it different from just continuing to not run services on the ports I would block?





Aucun commentaire:

Enregistrer un commentaire