All the cloud services I’ve used had virtual network firewalls for internal traffic. Security Groups for AWS, Cloud Firewall for GCP, etc. That’s typically how lateral traffic gets managed. Defense in depth is good, but as I said I haven’t used host firewalls in forever, and we get audited for security certificates every year, and no auditor has asked about them that I recall.
- 0 Posts
- 4 Comments
Joined 3 years ago
Cake day: July 1st, 2023
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.
- hypna@lemmy.worldtoTechnology@lemmy.world•Linux Firewalls: How to Actually Secure a Cloud Server (iptables, nftables, firewalld, ufw)English32·2 months ago
- hypna@lemmy.worldtoTechnology@lemmy.world•Linux Firewalls: How to Actually Secure a Cloud Server (iptables, nftables, firewalld, ufw)English311·2 months ago
These firewall tools are interesting, but I honestly haven’t needed them in years. The premise is a little out of date. Who puts cloud servers on the open internet these days? Everything I see uses a public load balancer and a WAF service.
You either put it in the DSL or people start writing generators for your DSL.
Maybe that’s the context. All of my cloud hosting work is very large corporate systems in the big three clouds. You’re talking about Hostinger or Scalahosting type services, yes?