Zorin os firewall is off by default

Hello.
I was looking at the settings section of zorin os and found the firewall settings field. I checked the status and it is off by default, why is this?
By the way, I have no knowledge about firewalls.
I would appreciate it if you could tell me.
Thank you in advance.

Π‘Π°ΠΌ ΠΏΠΎ сСбС брандмауэр Π½Π΅ слоТСн. Всё Π΄Π΅Π»ΠΎ Π² настройках, Ρ‚Π°ΠΌ Π³Π΄Π΅ ΠΎΠ½ΠΈ просты ΠΈ понятны, ΠΊΠ°ΠΊ Π² Mac OS ΠΏΡ€ΠΎΠ±Π»Π΅ΠΌ Π½Π΅Ρ‚, Π½ΠΎ Π² Windows ΠΈ Linux ΠΎΠ½ΠΈ ΠΈΠ»ΠΈ слоТны ΠΈΠ»ΠΈ Π½Π΅ понятны. НС стану ΠΏΡ€ΠΎΡΠΈΡ‚ΡŒ ΠΏΠΎΠΌΠΎΡ‰ΠΈ Ρƒ спСциалистов ΠΏΠΎ настройкС брандмауэра, Ρ‚Π°ΠΊ ΠΊΠ°ΠΊ ΠΏΡ€ΠΎΡ‡ΠΈΡ‚Π°Π» ΠΌΠ½ΠΎΠ³ΠΎ Ρ€Π΅ΠΊΠΎΠΌΠ΅Π½Π΄Π°Ρ†ΠΈΠΉ, Π½ΠΈΡ‡Π΅Π³ΠΎ Π²Ρ€Π°Π·ΡƒΠΌΠΈΡ‚Π΅Π»ΡŒΠ½ΠΎΠ³ΠΎ. Но я Π±Ρ‹ попросил Ρ€Π°Π·Ρ€Π°Π±ΠΎΡ‚Ρ‡ΠΈΠΊΠΎΠ² ΡΠΎΠ·Π΄Π°Ρ‚ΡŒ Π½ΠΎΡ€ΠΌΠ°Π»ΡŒΠ½Ρ‹ΠΉ ΠΈ простой Π² настройках брандмауэр. Π’ ΠΊΠΎΡ‚ΠΎΡ€ΠΎΠΌ ΠΌΠΎΠΆΠ½ΠΎ Π±Ρ‹Π»ΠΎ Π±Ρ‹ просто Π±Π»ΠΎΠΊΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ Π²Ρ‹Ρ…ΠΎΠ΄ ΠΊΠΎΠ½ΠΊΡ€Π΅Ρ‚Π½ΠΎΠΌΡƒ ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΡŽ Π² ΠΈΠ½Ρ‚Π΅Ρ€Π½Π΅Ρ‚, Π΄ΠΎΠ±Π°Π²ΠΈΠ² Π΅Π³ΠΎ Π² список ΠΈ ΡƒΠΊΠ°Π·Π°Ρ‚ΡŒ + ΠΈΠ»ΠΈ -

UFW is disabled by default because a firewall can interfere with many apps functionality.
Windows likes to hold the users hand and in return, all it asks for is Control.

On Linux, control is up to the user.
The user is responsible for ensuring that they only install software that requires root privileges when they have vetted the source.
If a user wishes to rely on a firewall, they can enable it and then allow or block ports as needed.
Linux operates differently, where you must authenticate (a lot) the actions you take with a password. The repositories you use already check packages being uploaded to them; such as Ubuntu and Debian Launchpad. Whenever I upload something to my repository, launchpad first installs it to a Virtual Test machine and checks it to ensure it behaves properly. Once it passes those tests, it then becomes available on APT.
The firewall is a good added measure of protection; but Linux encourages Learning, Growth and Knowledge rather than users giving up control for questionable security from a source that says "Trust me... Just trust me..."

In a car, a firewall is the bulkhead between the engine compartment and the vehicle occupants.
It acts as a solid buffer, preventing any engine fires from having access to the cabin.
This is not perfect, as smoke can get in through the Air Box (Vents). But it serves the function of preventing the fire from reaching the cabin swiftly. Occupants can escape the vehicle in plenty of time before the flames can reach the cabin.

In computers, the term was borrowed to demonstrate a buffer between The Outside Network and access to your computer.
Think of Ports as the same kind of ports that ships dock at to unload or load items. In this case, we can think of those ships as transporting Packets.
Packets access your computer and leave your computer through Ports.
If a port is open, packets can freely come and go - you can send and receive information and communication.
If a port is open - restricted, it can only send or receive packets from known or specific sources, rejecting any other sources.
If a port is closed, it cannot send or receive.
The Firewall governs the opening of ports - Allowing or Denying access.

2 Likes

I have mine on for incoming. Just had to punch holes for Zorin Connect and Plex. You can find the info here.

Как ΠΎΠΏΡ€Π΅Π΄Π΅Π»ΠΈΡ‚ΡŒ ΠΊΠ°ΠΊΠΎΠΉ ΠΈΠ· ΠΏΠΎΡ€Ρ‚ΠΎΠ² относится ΠΊ Ρ‚ΠΎΠΌΡƒ ΠΈΠ»ΠΈ ΠΈΠ½ΠΎΠΌΡƒ ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΡŽ? Допустим я Ρ…ΠΎΡ‡Ρƒ Π±Π»ΠΎΠΊΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ Π²Ρ‹Ρ…ΠΎΠ΄ Π² ΡΠ΅Ρ‚ΡŒ ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΠ΅ Cheese, ΠΊΠ°ΠΊ это ΡΠ΄Π΅Π»Π°Ρ‚ΡŒ, ΠΊΠ°ΠΊΠΎΠΉ ΠΏΠΎΡ€Ρ‚ Π±Π»ΠΎΠΊΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ?

Π― ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡŽ netstat. Π•ΡΡ‚ΡŒ ΠΈ Π΄Ρ€ΡƒΠ³ΠΈΠ΅ способы.
I use netstat, though there are other ways.

sudo netstat -ano -p tcp

Как Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Π²Ρ‹ ΡƒΠ·Π½Π°Π΅Ρ‚Π΅ свой ΠΏΠΎΡ€Ρ‚, Π²Ρ‹ ΠΌΠΎΠΆΠ΅Ρ‚Π΅ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚ΡŒ UFW, Ρ‡Ρ‚ΠΎΠ±Ρ‹ Π·Π°Π±Π»ΠΎΠΊΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ Π΅Π³ΠΎ (Π·Π°ΠΌΠ΅Π½ΠΈΡ‚Π΅ 1234 фактичСским Π½ΠΎΠΌΠ΅Ρ€ΠΎΠΌ ΠΏΠΎΡ€Ρ‚Π°).:

Once you know your port, you can use UFW to block it (replace 1234 with the actual port number):

sudo ufw deny 1234

:Π½Π΅ ΠΏΠΎΠ½Ρ€Π°Π²ΠΈΠ»ΠΎΡΡŒ:

Π’Ρ‹ ΠΌΠΎΠΆΠ΅Ρ‚Π΅ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚ΡŒ nmap, Ссли ΠΏΡ€Π΅Π΄ΠΏΠΎΡ‡ΠΈΡ‚Π°Π΅Ρ‚Π΅. Π― ΠΏΠΎΠ΄ΠΎΠ·Ρ€Π΅Π²Π°ΡŽ, Ρ‡Ρ‚ΠΎ Π²Π°ΠΌ Π½ΡƒΠΆΠ½ΠΎ ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠ΅ с графичСским интСрфСйсом для этого. Π― Π½Π΅ знаю Π½ΠΈ ΠΎΠ΄Π½ΠΎΠ³ΠΎ Π² Linux.


You can use nmap if you prefer. I suspect that you want a GUI application for it. I know of none in Linux.

sudo netstat -ano -p tcp Π’Π΅Ρ€ΠΌΠΈΠ½Π°Π» Π²Ρ‹Π΄Π°Π» Ρ‚Π°ΠΊΠΎΠΉ ΠΊΠΎΠΌΠ°Π½Π΄Ρ‹ Π½Π΅Ρ‚. Но это Π½Π΅ Π²Π°ΠΆΠ½ΠΎ. Π”Π° графичСский интСрфСйс Π±Ρ‹Π»ΠΎ Π±Ρ‹ Ρ…ΠΎΡ€ΠΎΡˆΠΎ. Π― умудрился Π½Π°ΡΡ‚Ρ€ΠΎΠΈΡ‚ΡŒ свой брандмауэр ΠΏΠΎΠ΄ сСбя. Но Π²Ρ€Π°Π·ΡƒΠΌΠΈΡ‚Π΅Π»ΡŒΠ½ΠΎ ΠΎΠΏΠΈΡΠ°Ρ‚ΡŒ это Π½Π΅ смогу. Надо ΡΠΊΠ°Π·Π°Ρ‚ΡŒ, Ρ‡Ρ‚ΠΎ брандмауэр ваТная Ρ‡Π°ΡΡ‚ΡŒ систСмы ΠΈ Π΅ΠΉ слСдуСт ΡƒΠ΄Π΅Π»ΠΈΡ‚ΡŒ особоС Π²Π½ΠΈΠΌΠ°Π½ΠΈΠ΅ Ρ€Π°Π·Ρ€Π°Π±ΠΎΡ‚Ρ‡ΠΈΠΊΠ°ΠΌ, Ρ‡Ρ‚ΠΎΠ±Ρ‹ Π½Π΅ ΠΏΡΠ»ΠΈΡ‚ΡŒΡΡ ΡƒΠ½Ρ‹Π»ΠΎ Π² Ρ‚Π΅Ρ€ΠΌΠΈΠ½Π°Π».

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.