canonical / canonical/ubuntu-server-documentation

[Suggestion]: Improvements to firewalls page

Open
#548 1 comment 0 reactions 0 assignees View on GitHub
size: M
Dominant language
Makefile
Stars
88
Forks
159
Avg merge
1d 13h
Merged PRs (30d)
5

Description

### Page URL

https://documentation.ubuntu.com/server/how-to/security/firewalls/

### Select an option

- [ ] I found what I was looking for
- [ ] I couldn't find what I was looking for
- [x] I found the information, but it was incorrect
- [x] I found the information, but it was incomplete
- [x] I found the information, but it was confusing
- [ ] I encountered a technical issue (e.g., broken link, image not loading)

### Issue Description

To discuss:

- Should reference `nftables` instead of `iptables` (`iptables` is a symlink to `iptables-nft` by default).
- Add a note to allow SSH access before starting `ufw` when activating it remotely.
- Rewrite IP masquerading section to use `nftables`. Probably reference https://wiki.nftables.org/wiki-nftables/index.php/Performing_Network_Address_Translation_(NAT)#Masquerading
- Mention default `ufw` logging in `/var/log/ufw.log` due to rsyslog
- "Check the status" should be right after "Enable or disable ufw" imo.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the firewalls page at documentation.ubuntu.com/server/how-to/security/firewalls/ and review the existing UFW, iptables, IP masquerading, logging, and command-order sections. Done means the page reflects nftables where requested, warns remote users to allow SSH before enabling UFW, documents /var/log/ufw.log, and places status checking after enable/disable instructions.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux, ubuntu
Domain
documentation, operating-systems, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
56/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.