Hacker News new | past | comments | ask | show | jobs | submit login

Pro tip: instead of changing ssh default port, setting up fail2ban and messing with iptables rules manually, just use ufw. You're welcome.



Is that a Ubuntu only tool? I'd be hesitant to commit myself to anything that runs in a single distribution if I can help it. Fail2Ban would work if I decided to migrate to Centos later down the line. https://help.ubuntu.com/community/UFW


It's an Ubuntu only tool in the same way that aptitude and dpkg-reconfigure are Ubuntu only tools.

The guide is not claiming to be generic, it's totally fair game to use specific tools imho - especially if they simplify things.


>the same way that aptitude and dpkg-reconfigure are Ubuntu only tools.

No. ufw can run on other distros, its just a frontend to iptables. A quick googling makes it look like its there in Arch repos, you have to compile yourself on CentOS. I don't know about all distros YMMV.

Even if ufw was Ubuntu specific, it would not be Ubuntu-specific in the way that aptitude and dpkg-reconfigure are. Those tools are Ubuntu specific because they're specific to that package manager.

And in actuality those tools aren't Ubuntu-only either. apt is the debian package manager and the tools should be present on any debian-based distro.


I'm pretty sure you completely misread that post.

"X is Y the same way that (false statement)" -> X is not Y


The number of completely wrong generalizations about distributions I hear by people being sincere prevents me from reading that as anything but one. People saying "only Ubuntu X" when they really mean "only debian-based X" is one of the most common mistakes I hear.

If I did misread it, that's an even worse thing to say. If a person is in the position of asking if ufw will work on CentOS, it is downright mean to give an answer that requires them understand esoteric particulars of the debian bloodline.


I don't know if I would call the package management system of debian esoteric in a conversation comparing distros. I will agree that the wording was a bad choice.


To my knowledge it is packaged only for Ubuntu, but it does work perfectly on centos.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: