Host Firewall

Contents
Essentials
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Essentials
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Essentials|Essentials]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Essentials](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Essentials)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Essentials](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Essentials)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Essentials]Essentials[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
The recommendation to install a host firewall is documented in the Computer Security Education section, along with basic settings.
Dedicated Connection
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Dedicated_Connection
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Dedicated_Connection|Dedicated Connection]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Dedicated Connection](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Dedicated_Connection)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Dedicated Connection](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Dedicated_Connection)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Dedicated_Connection]Dedicated Connection[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
If possible, it is safer to avoid sharing the network (LAN, Wi-Fi, hotspot) with other potentially compromised machines.
Filtering Ports
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Filtering_Ports
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Filtering_Ports|Filtering Ports]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Filtering Ports](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Filtering_Ports)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Filtering Ports](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Filtering_Ports)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Filtering_Ports]Filtering Ports[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Introduction
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Introduction
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Introduction|Introduction]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Introduction](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Introduction)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Introduction](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Introduction)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Introduction]Introduction[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
From time to time a user asks which incoming/outgoing ports are required by Template:Gateway product name. The answer is:
- Incoming:
none
. - Outgoing:
all
.
Incoming
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Incoming
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Incoming|Incoming]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Incoming](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Incoming)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Incoming](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Incoming)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Incoming]Incoming[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Template:Gateway product name itself does not open any ports. Users are advised to close all ports on the host as outlined in the Host Firewall Essentials entry.
Outgoing
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Outgoing
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Outgoing|Outgoing]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Outgoing](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Outgoing)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Outgoing](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Outgoing)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Outgoing]Outgoing[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Warning: This procedure is not recommended. Port-based filtering of outgoing traffic is not applicable (as in useful) in the case of Template:Gateway product name.
Filtering outgoing ports is difficult, since Tor entry guards or bridges listen on a variety of different ports. Limiting ports Tor uses for outgoing traffic is still possible, but recommended against, since it reduces anonymity. The effect is fewer entry guards or bridges are made available to the user. If users wish to proceed despite the risk, follow the instructions below.
On Template:Gateway product name.
Open /usr/local/etc/torrc.d/50_user.conf
.
If you are using Kicksecure inside Qubes, complete the following steps.
Qubes App Launcher (blue/grey "Q")
→ Kicksecure ProxyVM (commonly named kicksecure)
→ Tor User Config (Torrc)
If you are using a graphical Kicksecure, complete the following steps.
Start Menu
→ Applications
→ Settings
→ /usr/local/etc/torrc.d/50_user.conf
If you are using a terminal-only Kicksecure, complete the following steps. Click = Copy Copied to clipboard! sudo nano /usr/local/etc/torrc.d/50_user.conf
Add.
Click = Copy Copied to clipboard! ReachableDirAddresses *:80 ReachableORAddresses *:443 ## maybe: FirewallPorts PORTS ## See Tor manual: https://www.torproject.org/docs/tor-manual.html.en
Save.
Reload Tor.
After editing /usr/local/etc/torrc.d/50_user.conf
, Tor must be reloaded for changes to take effect.
Note: If Tor does not connect after completing all these steps, then a user mistake is the most likely explanation. Recheck /usr/local/etc/torrc.d/50_user.conf
and repeat the steps outlined in the sections above. If Tor then connects successfully, all the necessary changes have been made.
If you are using Kicksecure inside Qubes, complete the following steps.
Qubes App Launcher (blue/grey "Q")
→ Kicksecure ProxyVM (commonly named 'kicksecure')
→ Reload Tor
If you are using a graphical Kicksecure, complete the following steps.
Start Menu
→ Applications
→ Settings
→ Reload Tor
If you are using a terminal-only Kicksecure, click
HERE
for instructions.
Complete the following steps.
Reload Tor.
sudo service tor@default reload
Check Tor's daemon status.
sudo service tor@default status
It should include a a message saying.
Active: active (running) since ...
In case of issues, try the following debugging steps.
Check Tor's config.
sudo -u debian-tor tor --verify-config
The output should be similar to the following.
Sep 17 17:40:41.416 [notice] Read configuration file "/usr/local/etc/torrc.d/50_user.conf". Configuration was valid
This issue was also discussed in the old Template:Project name forum.
NAT Router
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#NAT_Router
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#NAT_Router|NAT Router]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[NAT Router](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#NAT_Router)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[NAT Router](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#NAT_Router)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#NAT_Router]NAT Router[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Being behind an ordinary NAT router might provide a marginal layer of extra security. In all cases, it is recommended to purchase a commercial-grade router and avoid cheap models, since they are often less-secure.
It is also suggested to review the entire Router and Local Area Network Security chapter, particularly:
- Recommended Router Settings.
- Advanced users: Flash the router with an open-source GNU/Linux distribution for better security, control and functionality.
Port Scan
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Port_Scan
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Port_Scan|Port Scan]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Port Scan](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Port_Scan)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Port Scan](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Port_Scan)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Port_Scan]Port Scan[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Using an Internet-based port scanner service to test the local LAN's router/firewall is a sensible idea. Users must carefully research and find a legitimate service, since many companies only want to sell a product and will purposefully present false positives. A better alternative is to scan the local LAN with a port scanning application from an external IP address. To scan the home IP address, users can either login remotely (SSH) via an external machine, or proxy through an external IP address. Detailed instructions on accomplishing that are beyond the scope of this document.
A special case is presented by users who share a LAN with other PCs (a stand-alone machine is not used). In this instance, the port scanning/testing service or a port scan application from an external IP address will actually only scan the local LAN's router/firewall and not the actual host's PC. If the latter is mis-configured, then the user could be susceptible to attacks from other machines within the LAN which sit behind the router, and a false sense of security could be the result.
For example, if the user shares the LAN with flatmates who are not so sophisticated in computer security, then those foreign machines should be regarded as potentially malicious. There is every possibility they may have been infected with a botnet already or other harmful programs. Therefore, the user cannot trust the output of a port scan application running on their machine. If there is no spare machine for testing, then foreign computers on the LAN can be booted from a live CD, and the user can scan their personal machine with a port scan application. Details on how to accomplish that task are also outside the scope of this document.
Footnotes
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Footnotes
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Host_Firewall#Footnotes|Footnotes]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Footnotes)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Footnotes)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Host_Firewall?direction=next&oldid=52781#Footnotes]Footnotes[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.


Copy as Wikitext

for Discourse, reddit, GitHub

Copy as Markdown

Copy as phpBB Click below ↴ = Open social URL with share data











We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!