For services reachable from the internet I am aiming at client certificate authentication where possible, but that's a bit of a different topic than firewalling.
Quote from: bimbar on November 05, 2021, 12:55:05 pmFor services reachable from the internet I am aiming at client certificate authentication where possible, but that's a bit of a different topic than firewalling.Still you need to open port 443 for the reverse proxy implementing that. That's what I was referring to.Yes, reverse proxy for a single point of SSL termination is definitely recommended and can do much much more.Did I mention Apache Guacamole for remote access of SSH/VNC/RDP? Can do 2FA, too.