/srv/irclogs.ubuntu.com/2020/01/05/#ubuntu-server.txt

SkyriderCan I ask a ufw related question here?09:42
SkyriderMight as well.. Used ufw to block an ip range x.x.0.0/16, yet it doesn't appear to work. All the other ufw rules are working, just not this ranged deny I created.09:48
tomreynSkyrider: i would not recommend ufw for a server firewall. rather use iptables directly or some framework around it such as shorewall.12:58
JanCwell, ufw is a framework around it12:58
tomreynyes, but... not a complete or really good one12:59
JanCit should be able to do what most people need for a simple server, no?13:02
tomreynyes, as long as they don't use the GUI for managing it.13:03
tomreynthats my personal POV, anyways13:04
JanCufw itself doesn't have a GUI13:04
tomreyngufw is a separate package, but i think it's preinstalled.13:05
tomreyn...on desktops13:05
JanCI doubt it is13:05
JanCit never supported ufw correctly, and hasn't been updated in a decade probably?13:06
tomreynhmm its in universe, probably not then, right13:06
SkyriderUsing ufw as I prefer its simplicity.13:07
tomreynso let's say ufw can be fine, just dont use gufw13:07
JanCSkyrider: I assume you didn't forget to reload the firewall after adding that rule?13:07
JanCalso "doesn't appear to work" is rather vague13:09
Skyriderall rules added through ufw should be instantly loaded.13:13
SkyriderAs for gufw, don't see a point in that seeing I use a headless server.13:13
SkyriderAnd "doesn't work", I blocked an ip range and had to block the IP range in nginx as well. The blocked IP's keeps showing up in nginx's logs, while it shouldn't be logged at all as ufw should deal with it.13:14
SkyriderMaybne ufw ip range deny/reject is borked?13:14
JanCthere is no other rule overriding it?13:15
SkyriderGuess that's a fair point I haven't considered. allow port 80 I suppose.13:16
SkyriderBut shouldn't deny/reject override allow?13:16
SkyriderIt is listed in iptables: -A ufw-user-input -s 159.138.0.0/16 -j REJECT --reject-with icmp-port-unreachabl                                                                                                                                                             e13:17
SkyriderAs for ufw, was last updated 2018-12-1413:19
JanCrule ordering?13:22
JanCyou'd need to have the deny for that range before the one to allow port 8013:23
JanCas the first one that matches will be applied13:25
JanCSkyrider: ^^^13:30
SkyriderThanks JanC, but I double checked. All rejects in ufw are set to top.13:40
Skyrider[10] Anywhere                   REJECT IN   159.138.0.0/1613:40
Skyrider[11] 80/tcp                     ALLOW IN    Anywhere13:40
Skyrider1 to 9 are also rejects.13:40
=== vlm_ is now known as vlm
=== tops is now known as jobs
=== jobs is now known as tjobsl
=== tjobsl is now known as tops

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!