Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not a sysadmin, but it seems even safer and easier to 1) keep Windows behind NAT, 2) ssh port forward through UFW on a cheap Linux box.


If you have the luxury to do that, but if you run a VM, or a single box in colocation, or rent a physical server, that may not be an option. My point is introducing an IP whitelist inside the server doesn't require to change the physical set up, nor any current process relying on the server being directly accessible. It's a low cost quick win.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: