The networkEvery page
Firewall
The Firewall page says whether it is on, what may come in from the internet, and how many devices are kept away from something. Then four tabs: Rules, Put in order, Port forwards and Settings.
Every change here waits to be kept.
Rules
First the blocks for one device (made on the Network page), then each part of the firewall as rows of words with how often each rule matched:
- Reaching this machine: what may talk to the machine itself.
- Passing through: what may cross it, between your home and the internet (a router's).
- Leaving this machine: what the machine itself may send.
A row opens its editor. The rules the modules need come after yours, read-only: an app's port, open to your home network while the app is on. A block of yours still wins over them.
Put in order
Arrows on each row, and a bar above them. Moves are made on the page and Apply sends the whole order at once, to be kept.
Port forwards
A router's: a port on the internet side sent on to a device at home, a row each.
Settings
What happens to what no rule matches, how many rules are yours, and putting back the default rules.
On a machine that is not a router
It has the base firewall, made from what is switched on. Open: the panel, port 80 (which only sends you on to the panel), SSH and ping, and what the modules need. An app's ports are open to the machine's own private networks only, never a public one. Everything else coming in is dropped, and nothing passes through.
Your own rules come after those, and replies are let out before any of yours, so no rule can close the panel or SSH to you.