-
Notifications
You must be signed in to change notification settings - Fork 10.7k
Open
Labels
content:editRequest for content editsRequest for content editsdocumentationDocumentation editsDocumentation editsproduct:cloudflare-one
Description
Existing documentation URL(s)
What changes are you suggesting?
The "OS-level firewall rules" section provides iptables commands to block ingress traffic, but does not mention that these rules are temporary and will be lost on reboot. This is a significant omission because:
- Users following this guide expect their server to remain protected after implementing these firewall rules
- After a reboot, all iptables rules are cleared, leaving services directly exposed to the internet
- This defeats the purpose of the "positive security model" the documentation describes
Suggested fix:
Add a note or additional step after the iptables commands explaining how to make the rules persistent. For example:
Debian/Ubuntu:
sudo apt install iptables-persistent
sudo netfilter-persistent saveAdditional information
No response
Metadata
Metadata
Assignees
Labels
content:editRequest for content editsRequest for content editsdocumentationDocumentation editsDocumentation editsproduct:cloudflare-one