#Ufw

Verfassungklage@troet.cafeVerfassungklage@troet.cafe
2025-06-10

Was ist #iptables-persistent?

Und wie unterscheidet es sich von #UFW? (Iptables Teil 1)

Wer mit der #Linux-Firewall iptables arbeitet, trifft früher oder später auf das Paket iptables-persistent. Was ist das genau – und worin unterscheidet es sich von der einfacheren Alternative UFW?

Die integrierte #Firewall #iptables ist auf den meisten GNU/#Linux-Systemen verfügbar und bietet eine leistungsfähige Möglichkeit, Netzwerkzugriffe zu kontrollieren.

gnulinux.ch/was-ist-iptables-p

2025-06-10

Was ist iptables-persistent? Und wie unterscheidet es sich von UFW? (Iptables Teil 1)

Wer mit der Linux-Firewall iptables arbeitet, trifft früher oder später auf das Paket iptables-persistent. Was ist das genau – und worin unterscheidet es sich von der einfacheren Alternative UFW?

#iptables #Firewall #Ufw #Netzwerksicherheit #iptables_persiste #Linux

gnulinux.ch/was-ist-iptables-p

2025-06-08

#ufw macht das leben schon erheblich einfacher....

2025-06-06

Showed up with my brothers and sisters to show our legislators that we need financial support to keep the wheels on the bus. It was a great rally, thousands showed up. #unionstrong #afscme #seiu #ufw #oregon #cutbackfightback #SalemOregon

A bunch of union members at a rally outside of the Oregon State Capitol building on a Thursday. The Capitol is a large, brutalist building with a golden statue of a 'Pioneer Man' on the top.
albi always therealbi@f.cz
2025-05-19

konec #IPTables je v dohlednu, částecně už i na dosah
za poslední rok jsem investoval čas a z předchozích #UFW a mrtvého #Shorewall přeskočil #FirewallD rovnou do nahatých #NFTables

- UFW využívá na pozadí iptables automaticky překládané do nftables, což je paskvil, který může vyhovovat závislákům na prehistorických iptables souborech "na které se nešahá", ale progresivnějšímu uživateli dost svazuje ruce
- navíc je nutné mít namemorovanou jejich speciální syntaxi a hlavně skladbu argumentů, takže většinou zadám validní příkaz na asi 4. pokus

- FirewallD si samozřejmě taky vymyslel vlastní příkazovou syntaxi, ale zároveň zapleveluje nftables nepoužívanými chainy, přijít k cizímu stroji a udělat nějakou drobnou úpravu v pravidlech je skoro na nobelovku

- NFtables jsou za mě nejpřehlednější a nejspolehlivější (největší kontrola), navíc umožňujou mít totální kontrolu nad firewallem a poslat k šípku snahy Dockeru o nadvládu
- navíc jsou velmi jednoduché a snadno pochopitelné

Lucas Janin 🇨🇦🇫🇷lucas3d
2025-05-12

My transition from to is complete. I created 2 LXC Caddy instances: one for public services (with ) and another for my private ones. This setup limits exposure to potential unwanted visitors.

Now, my cluster is available with load balancing for both IPv4 & IPv6.

Globally, the transition is easy. I only have some trouble blocking the outside traffic on Headscale Admin, with the reverse proxy of Pi-hole Admi/API, and of course, IPv6.

Proxmox admin with my two Caddy instances (LXC Debian)My caddyfile for my Proxmox  cluster

## Proxmox 
pve.xx.xx {
	reverse_proxy * {
		to https://x.x.x.x:8006
		to https://[x:x:x:x::x]:8006
		to https://x.x.x.x:8006
		to https://[x:x:x:x::x]:8006
		lb_policy first
		lb_try_duration 1s
		lb_try_interval 250ms
		health_uri /
		health_interval 10s
		health_timeout 2s
		health_status 200
		header_up Upgrade {http.request.header.Upgrade}
		header_up Connection {http.request.header.Connection}
		header_up Host {upstream_hostport}
		transport http {
			tls_insecure_skip_verify
		}
		# Optional: Uncomment if you want health checks
		# health_uri /
		# health_interval 10s
		# health_timeout 2s
		# health_status 200    }
	}
}
2025-05-08

“They Actually Had a List”: #ICE Arrests Workers Involved in Landmark #LaborRights Case

“We are concerned at the appearance of targeting publicly #ProUnion worker leaders,” said a union official about a raid in western New York.

Noah Hurowitz
May 5 2025

"An immigration raid in western #NewYork on Friday targeted a group of immigrants involved in a landmark statewide effort by #FarmWorkers to #unionize.

"On Friday morning at around 9:30 a.m., federal agents in unmarked cars and bearing no agency insignia pulled over a bus in Albion, New York, about 35 miles west of Rochester, and took 14 people of Lynn-Ette & Sons Farms into custody. All of the detainees, who hailed from Mexico and Guatemala, were year-round employees of Lynn-Ette & Sons Farms, a family-owned business in nearby Kent, New York, which has been locked in a multiyear battle to prevent workers from unionizing.

"The company is one of five agricultural businesses that, together with a state growers’ association, have tried for years to overturn or chip away at New York’s 2019 #FarmLaborLaw. The law enshrined protections for the right of #farmworkers — whether seasonal or year-round — to seek union representation.

" 'This was strange because they actually had a list of most of the workers on the bus.'

"Several of the workers taken into custody on Friday have been active in efforts to unionize year-round employees, including at least one who has spoken publicly in favor of joining the United Farm Workers of America, according to Elizabeth Strater, director of strategic campaigns for #UFW, the storied labor union.

" 'We are concerned at the appearance of targeting publicly pro-union worker leaders,' said Strater.

"Most of the workers detained on Friday hail from #Mexico or #Guatemala.

"The raid did not appear to be a broad sweep but rather a targeted enforcement aimed at specific people, according to sources who have been in contact with the families and spoke to The Intercept on condition of anonymity to candidly discuss a sensitive legal situation."

Read more:
theintercept.com/2025/05/05/ic

Archived version:
archive.ph/xLMYr

#UnionBusting #ResistICE #Fascism #USPol #ICESucks #NoFarmWorkersNoFood #UnitedFarmworkers #FarmLaborUnions

Peter Link 🍉🇨🇺🇵🇸🐧Peter_Link@expressional.social
2025-05-06

“They Actually Had a List”: #ICE Arrests Workers Involved in Landmark Labor Rights Case

“We are concerned at the appearance of targeting publicly pro-union worker leaders,” said a union official about a raid in western #NewYork.

from #TheIntercept
Noah Hurowitz
May 5 2025, 6:27 p.m.

theintercept.com/2025/05/05/ic

#StopTheDeportations #immigrants
#WorkersRights #Workers #Unions #Labor #LaborMovement #LaborUnions #USA #US #USPolitics #sindicatos
#UFW #press #news

I was trying to use iptables decided that life is too short for this hobbyist to go down that path, so installed ufw and saw there was an XMPP app profile when doing ufw app list.

Brilliant, this should be easy then!
WRONG.

This is what ufw app info XMPP gave:

Profile: XMPP
Title: XMPP Chat
Description: XMPP protocol (Jabber and Google Talk)

Ports:
5222/tcp
5269/tcp
Which is um... not many ports. And naturally broke things like image uploading.

So I wrote my own in a new file at /etc/ufw/applications.d/ufw-prosody like this:

[Prosody]
title=Prosody XMPP
description=Prosody XMPP Server ports per https://prosody.im/doc/ports
ports=5000,5222,5223,5269,5270,5281/tcp
Which after saving, doing ufw app update Prosody,
then ufw app info Prosody now gives:

Profile: Prosody
Title: Prosody XMPP
Description: Prosody XMPP Server ports per https://prosody.im/doc/ports

Ports:
5000,5222,5223,5269,5270,5281/tcp
ufw allow Prosody to apply (allow) the rules and all is well again.

❤️
#XMPP #Prosody #ufw #iptables #firewall
2025-04-18
Comparing firewall syntax for SSH (port 22) with default-deny:
================================================

#iptables (Linux)
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -P INPUT DROP

#nftables (Linux)
nft add rule inet my_filter input tcp dport 22 accept
nft add rule inet my_filter input drop

#ufw (Linux - simplified frontend to iptables)
ufw allow 22/tcp
ufw default deny incoming

#pf (OpenBSD)
pass in proto tcp to port 22
block all

pf’s syntax feels so elegant, human-readable, & minimal!

After 20years scripting iptables, I’m ready to try UFW on my laptop.
#firewall #sysadmin #pf #iptables #ufw #nftables

I'm thinking about helping a #senior friend move to #Linux instead of upgrading from #Windows 10 to 11. Wondering what #security #apps I should install for them... Or any apps in general?

Is it still the case that Linux doesn't need #antivirus #software? Or if it does, what's recommended? Is it reasonable to assume I can install and configure #UFW and not worry about them calling me up asking about popups or why something's not working?

What are good set-and-forget apps/settings?

#foss

2025-03-31

Today in Labor History March 31, 1927: Birth of Cesar Chavez. In 1965, Chavez led farm workers in California on their first grape boycott. The nationwide protest lasted five years and ended with the first union contract for U.S. farm workers outside of Hawaii. In 1966, Chavez’s organization officially became the United Farm Workers. Chavez was inspired by the nonviolent civil disobedience of Gandhi. In addition to strikes, boycotts and pickets, he was famous for going on hunger strikes. Later he became infatuated with the religious cult, Synanon. He used Synanon’s “game” to punish union members and enforce conformity. Chavez also supported the brutal Filipino dictator Ferdinand Marcos. This alienated Filipino members of the union, as well as many of the religious organizations that had supported the UFW.

#LaborHistory #workingclass #CesarChavez #FarmWorkers #ufw #chicano #mexicanamerican #union #strike #boycot #filipino #hungerstrike

Chavez photographed in 1972. By Keyes, Cornelius M. (Cornelius Michael), 1944-, Photographer (NARA record: 8463989) - U.S. National Archives and Records Administration, Public Domain, https://commons.wikimedia.org/w/index.php?curid=16184557
2025-03-25

Настройка форвардинга на UFW для Ubuntu Server

UFW (Uncomplicated Firewall) - это утилита для управления пакетами брандмауэра в Linux, которая предоставляет удобный интерфейс для настройки iptables. Он создан для упрощения процесса управления сетевыми правилами и подходит как для новичков, так и для опытных администраторов. NAT (Network Address Translation) — это метод, позволяющий изменять адреса IP в заголовках пакетов, проходящих через маршрутизатор или брандмауэр. Он часто используется для обеспечения доступа к ресурсам из локальной сети в Интернет, скрывая внутренние IP-адреса от внешней сети.

habr.com/ru/articles/894316/

#ubuntu #ubuntu_server #ufw #nat

M3Imaginationmvsiii71
2025-03-24

🇲🇽❤️ Mexican immigrants are fundamental to America's foundation, contributing to our culture, economy, and communities. Their hard work and resilience continue to shape the nation we love. Let's honor their legacy and recognize their vital role in our shared story! 🇺🇸

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst