Skip to content

ReferenceThe 22 checks

Firewall

Security checkfirewall

What it reads

Whether ufw, firewalld or an nftables or iptables rule set is on.

Does it need root?

It needs root for part of what it reads. When ufw and firewalld are off, reading nftables or iptables rules needs root. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • The firewall is on (firewall)

What it can find

Warning

No firewall is on

Without a firewall, every port a program opens can be reached from the internet.

Fix
sudo ufw allow OpenSSH && sudo ufw enable