Firewall Configuration
By default, Dalet Flex requires a flat network configuration.
It translates by:
- all instances are part of the same private LAN subnet.
- all instances can reach others by direct IP connection.
- no instance (but load-balancer) is accessible from public network (e.g. Internet)
making things fairly secure, provided that you trust your private network (i.e. no co-existing third-party blackbox system).
Exposure to broader, possibly insecure network (e.g. Internet) is restricted to dedicated load-balancer instances (limited to HTTP(s) ports), further offloading SSL traffic and routing application requests to the necessary internal instances.
The load-balancer, being exposed, and more than recommended to be backed by a firewall.
When using LBaaS (e.g. AWS ALB), this is usually done by use of appropriate security groups.
When running on-premises, this is usually done by a top-level third-party firewall (hardware or software), e.g. Cisco, Palo Alto ...
Flex instances are then considered safe, as only exposed in a limited private subnet.
If security is to be enhanced, this can be done by adding a software firewall on the various instances.
Relying on Ubuntu Linux, this can quite easily be done by simply turning on the following deployment variable in ansible/vars/variables.yml file:
dalet_baseos_network_firewall_enabled: true
Once enabled, Linux nftables rules will be applied with deny-all policy, meaning that no traffic but the whitelisted one will be accepted.
It is then up to you to explicitly enable exceptions rules, specifying the necessary TCP and UDP ports not to be filtered, for example:
dalet_baseos_network_firewall_open_tcp_ports:
- 80
- 443
dalet_baseos_network_firewall_open_udp_ports: []
would reject all traffic but HTTP(S) requests.