{"id":867,"date":"2012-03-21T15:40:35","date_gmt":"2012-03-21T22:40:35","guid":{"rendered":"http:\/\/blog.networkpresence.co\/?p=867"},"modified":"2014-02-20T18:16:14","modified_gmt":"2014-02-21T01:16:14","slug":"firewalls-for-customers-on-our-vps-networks","status":"publish","type":"post","link":"http:\/\/blog.networkpresence.co\/?p=867","title":{"rendered":"Firewalls for Customers on our VPS &#038; Networks"},"content":{"rendered":"<p>Some customers would like Firewalls around their VPS or Colocation hosts and networks, we know, but they don&#8217;t know who to ask to get them setup or how to go about it, so we&#8217;ve created a few simple Plans for &#8220;Customer Firewalls&#8221; for Network Presence customers.<\/p>\n<p>It&#8217;s as easy as being Firewall Rules for $2 \/ Rule \/ month, min. spend of $12 \/ month, for Firewalls that &#8220;Allow a Few Ports, then Block the Rest&#8221;. Of course as part of that <a href=\"http:\/\/netpr.es\/contactus\" title=\"Contact Network Presence\" target=\"_blank\">we&#8217;ll help you craft those Firewall Rules<\/a> to deliver the protection you&#8217;d like for your site or servers hosted within Network Presence.<\/p>\n<p>We also know that there&#8217;s customers that want to have just a few &#8216;ports&#8217; opened and those that want to be &#8220;mostly open, few filtered&#8221; TCP or UDP ports and we can accomodate that too, as listed in the following.<\/p>\n<p>Rules may look like:<\/p>\n<p>a) Baseline Web Server, no SSL, just &#8220;port 80&#8221;<\/p>\n<p>Allow Port 80 sessions from the Internet<br \/>\nBlock anything else<\/p>\n<p>That&#8217;s 2 Rules, min. spend of $12 \/ month.<\/p>\n<p>b) Commerce Web Server, including SSL<\/p>\n<p>Allow Port 80 sessions from the Internet<br \/>\nAllow Port 443 sessions from the Internet<br \/>\nBlock anything else<\/p>\n<p>That&#8217;s 3 Rules, at $2 \/ Rule it&#8217;s under the min. spend of $12 \/ month.<\/p>\n<p>c) Business Server, Web and Email<\/p>\n<p>Allow Port 80 sessions from the Internet<br \/>\nAllow Port 443 sessions from the Internet<br \/>\nAllow Port 25 sessions from the Internet<br \/>\nAllow Port 110 (POP3) sessions from the Internet<br \/>\nAllow Port 995 (POP3S) sessions from the Internet<br \/>\nAllow Port 143 (IMAP) sessions from the Internet<br \/>\nAllow Port 993 (IMAPS) sessions from the Internet<br \/>\nBlock anything else<\/p>\n<p>That&#8217;s 8 Rules and at $2 \/ Rule it&#8217;s also under the min. spend of $16 \/ month.<\/p>\n<p>d) Business Server, Web, FTP, Email and CMS<\/p>\n<p>Allow Port 80 sessions from the Internet<br \/>\nAllow Port 443 sessions from the Internet<br \/>\nAllow Port 25 sessions from the Internet<br \/>\nAllow Port 110 (POP3) sessions from the Internet<br \/>\nAllow Port 995 (POP3S) sessions from the Internet<br \/>\nAllow Port 143 (IMAP) sessions from the Internet<br \/>\nAllow Port 993 (IMAPS) sessions from the Internet<br \/>\nAllow Port 8080 (custom CMS) sessions from a single host on the Internet (1 rule)<br \/>\nAllow FTP sessions from 2 hosts on the Internet (2 rules)<br \/>\nAllow CMS custom port sessions from 2 hosts on the Internet (2 rules)<br \/>\nBlock anything else<\/p>\n<p>That&#8217;s 15 Rules and at $2 \/ Rule it&#8217;s $30 \/ month.<\/p>\n<p>The advantage of the way that we do our Firewalls is that you need to enable a &#8220;Port or Service&#8221; (eg: Port 8080 of a CMS or &#8220;Mail&#8221; (being POP\/POP3S\/IMAP\/IMAPS)) for it to be accessible, so by default your IP address becomes &#8220;unaccessible&#8221; from outside of Network Presence.<\/p>\n<p>Inside of Network Presence though you can continue to access your Firewalled site and IP address. This is deliberate, in that we recommend that you have an <a href=\"EveryNet ADSL connection\" title=\"EveryNet National ADSL\" target=\"_blank\">EveryNet ADSL connection<\/a> to the Internet, which brings you into Network Presence&#8217; network perimeter and inherently better access to services hosted by Network Presence.<\/p>\n<p>If you want &#8220;Block a Few then Allow All&#8221; type Firewalls then we can do that too, but it&#8217;s a different Firewall methodology in that it logs exceptions and it&#8217;s priced accordingly slightly higher than the &#8216;permit a few, deny the rest&#8217; being $3 \/ Rule, like the following templates. It&#8217;s as easy as being Firewall Rules for $3 \/ Rule \/ month, min. spend of $20 \/ month. We&#8217;ll help you craft those Firewall Rules to deliver the protection you&#8217;d like for your site or servers hosted within Network Presence.<\/p>\n<p>a) Internet server only for our Office on a Static IP ADSL\/NBN\/Internet service<\/p>\n<p>Allow new Port 80 sessions from the Internet into the IP address of the Office and Count them (2 Rules)<br \/>\nAllow new Port 443 sessions from the Internet into the IP address of the Office and Count them (2 Rules)<br \/>\nBlock un-connected TCP packets from the Internet into the IP address of the Office (1 Rule)<br \/>\nAllow anything else (1 Rule)<\/p>\n<p>That&#8217;s 6 Rules, at $3 \/ Rule means that it&#8217;s at the min. spend of $20 \/ month for &#8220;Block Some, Allow Most&#8221;.<\/p>\n<p>b) Internet Server to the Internet, just a few exceptions<\/p>\n<p>Block new Port 8080 sessions from the Internet except for our 3 Static IP Addresses (4 Rules)<br \/>\nLog Exceptions to that port 8080 access (1 Rule)<br \/>\nAllow new Port 443 sessions from the Internet into the IP address of the Office and Count them (3 Rules)<br \/>\nBlock un-connected TCP packets from the Internet into the IP address of the Office (1 Rule)<br \/>\nAllow anything else (1 Rule)<\/p>\n<p>That&#8217;s 10 Rules, at $3 \/ Rules means $30 \/ month for that sophisticated Firewall<\/p>\n<p>All in all, we have two Firewall Plans, one that&#8217;s &#8220;block some, allow all&#8221; and another that&#8217;s &#8220;allow a few, block the rest&#8221; and they&#8217;re available to any customer within the Network Presence network and billed directly by Network Presence. There&#8217;s also a customer-maintained web based interface to updating the Firewall Rules, so there&#8217;s minimal need to contact us for you to update your Firewalls yourself.<\/p>\n<p>Please <a href=\"http:\/\/netpr.es\/contactus\" title=\"Contact Network Presence\">contact us<\/a> to discuss your Firewall requirements, regards,<br \/>\nRichard.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some customers would like Firewalls around their VPS or Colocation hosts and networks, we know, but they don&#8217;t know who to ask to get them setup or how to go about it, so we&#8217;ve created a few simple Plans for &hellip; <a href=\"http:\/\/blog.networkpresence.co\/?p=867\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,70],"tags":[27,139,78,9],"class_list":["post-867","post","type-post","status-publish","format-standard","hentry","category-network-presence","category-sales","tag-appliance","tag-firewall","tag-sysadmin","tag-vps"],"_links":{"self":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=867"}],"version-history":[{"count":33,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/867\/revisions"}],"predecessor-version":[{"id":4668,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/867\/revisions\/4668"}],"wp:attachment":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=867"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}