Skip to main content

UFW / Firewall management

Opening / closing ports directly from the dashboard as well as adding pre/post route advanced rules
Status: In Progress18 comments

Log in to comment and vote

Comments18

  • Arni Johannesson changed status to In Progress
    Team•

    Sep 6, 2023

    This is now in progress

  • Arni Johannesson changed status to Planned
    Team•

    Sep 29, 2022

    Moving this to planned as there is clearly a lot of interest in this feature. We will update once we know where this fits into our development pipeline.

  • Cezar

    •

    Sep 29, 2022

    Not ufw. This must be in front of the servers, not at the OS level. This is so critical considering the servers are publicly available on the internet. If you run docker, you’re completely exposed as docker manages iptables rules to allow container networking to work. You can place a Palo Alto or a large host with SDN in front of the VMs and manage FW rules from the web interface for each VM using REST.

    • Arni Johannesson

      Team•

      Sep 29, 2022

      Cezar: Hello Cezar - one thing doesn't exclude the other. We want to allow for easy UFW management in our Dashboard and then probably in the future we would consider DC-level firewalling as an add-on to your server (like most other providers do it) I will add this as a seperate feature request here shortly.

    • Arni Johannesson

      Team•

      Sep 29, 2022

      Cezar: I added it just now, here: https://webdockio.canny.io/feature-requests/p/datacenter-level-firewall-option

    • Arni Johannesson

      Team•

      Sep 29, 2022

      Epsilon PS _ Paul Schiffer: Yes when logged in as admin I get that URL forced upon me - sorry I didn't notice. It's the same page so not a big deal. Thanks for flagging it :)

    • Arni Johannesson

      Team•

      Sep 29, 2022

      Epsilon PS _ Paul Schiffer: No unfortunately we have exhausted all branding options with Canny - there are more things than what you mention we'd like to be able to do (like, link the header logo back to our main website), but for now this is what we get with Canny.

    • Arni Johannesson

      Team•

      Oct 24, 2022

      Epsilon PS _ Paul Schiffer: Got it. We are scheduling a call with the folks at Canny soon where I will bring up these details. Thanks.!

  • Arni Johannesson changed status to In Review
    Team•

    Sep 28, 2022

    We would like to see how many upvotes this feature gets before committing to it.

  • Beda Schmid

    •

    Oct 28, 2024

    I disagree with this.

    1. For some reason at some point WD has enabled a feature (and suggests to use it) that allows removal/hiding of SSH users in the Admin Panel. By my understanding this was done with security in mind as in “if someone unexpected gets into the Admin panel” etc etc
    2. Thus, allowing someone to edit UFW in the Admin Panel for me is a showstopper. IMO this should only be edited on the server directly, by an SSH’d user.

    For the concern of:
    > If you run docker, you’re completely exposed as docker manages iptables rules to allow container networking to work.

    … please do not use Docker like that if opening ports is a concern.

    You can use docker perfectly fine WITHOUT exposing any ports by mapping it to the same network as your proxy server and in it, forward everything to your_container:PORT (or use the localhost IP 127.0.0.1:PORT:PORT in the docker container and proxy to 127.0.0.1:PORT in your proxy server such as caddy)

    This should definitely not be an argument for allowing someone to edit UFW (or worse, IPTABLES) in the webdock admin.

    Perhaps I misunderstand the request - please correct me if so. However if I understood it correctly, thumbs down - and an immediate follow up request to be able to turn this off, if it gets implemented :)

    • Epsilon PS _ Paul Schiffer

      •

      Apr 25

      You stated valid concerns, however details are missing.

      The reason this was brought up at all is because a datacenter-level firewall large enough to handle all traffic is expensive (money-, process- and planning-wise) and only feasible as a long-term project, if at all.

      So the ufw management, for the non-expert users of the vps, would’ve increased security easily by removing the cli hurdle. Yes, in times of AI, the hurdle lessened, but its still there.

      A firewall in front of the server is always better, and because the hypervisor in use changed, I believe its now more attainable than 3+ years ago when this feature was first suggested.

      The vision for this should for example be the way Hetzner does it with their pure cloud VMs, with the firewall feature. No switch-level ACL dumb stuff like with the dedicated servers.

      And on docker combined with ufw:

      Sure, if carefully setting the port forwardings, it can be done safe, but many docker users use pre-done docker-compose files or other commands, not built for public VPS with direct public IPs.

      And the real question also is, how many Webdock VPS customers actually use docker, only where the docker ufw issue is relevant.