Firewall
Firewall settings are a means of protecting the system from network attacks. Incoming ports that are not needed should be blocked. Even better than that, however, is not to start any services that open these ports. The necessary settings require an overview of the ports used that is coordinated with everyone involved.
A firewall can be used to filter the network packets that are passing through. Depending on the firewall technology, filter rules can be formulated on the basis of address, port, state of communication relationship, content of the packet, and much more. Firewalls are thus a tool to reduce the attack surface.
A firewall can be implemented as additionally installed software, as part of the operating system, or as a self-contained device. Each of these forms has advantages and disadvantages. A host-based firewall provides protection directly on the system, while an external firewall can filter network traffic centrally.
Firewalls with deep-packet inspection, which also evaluate the user data of the data packets, are not able to see the contents of encrypted connections. In order to be able to process the content (e.g. web applications), encryption is often terminated at the firewall and the data for the client is re-encrypted. As a result of this, the contents are visible to the firewall, but the end-to-end encryption is interrupted.
Restrictive, explicit settings for communication via a firewall are an important measure to allow network access only to the necessary extent.
Important TCP/UDP ports contains a list of TCP/UDP ports that typically need to be considered in order to configure a firewall.
In Beckhoff RT Linux®, packet filtering is performed using netfilter with nftables. This allows you to define rules for incoming, outgoing, and forwarded network connections.
You can view the currently active firewall configuration by running sudo nft list ruleset. Even if the standard file /etc/nftables.conf exists on the system, it is not used as the primary configuration file on that system. The file nftables, loaded by the /etc/nftables-bhf.conf service, is the key file; it includes additional rule files from /etc/nftables.conf.d/. This enables a modular and more maintainable structure for the firewall rules.
When configuring the system, you must ensure that only the connections actually required for operation are enabled. You should disable any ports and services that are not needed, or block them using appropriate filter rules. If both secure and insecure communication options are available, you should, whenever possible, enable only the secure options.
You should review changes to the firewall configuration after commissioning and after software updates to avoid unintentional openings or blocked communication paths.