Currently the ufw software is unable to perform application level filtering protection of traffic. So once you open the port to a specific protocol and ip address then any software can use it. Which can potentially be a security risk if the port is needed but a malicious program were to use it as well.
However if the ufw were capable of providing application level filtering of traffic it could really help to boost security of all systems with it installed, configured and running. It would as a result then harden the Ubuntu Linux even further than without. As well as provide even more information to those administering systems as connections for applications which are blocked would be logged.
So can the ufw software be updated in time for the release of 18.04 LTS? May be worth an exception by those responsible for project management.
Distro Version: Ubuntu 16.04 LTS
UFW Version: 0.35-0ubuntu2
Currently the ufw software is unable to perform application level filtering protection of traffic. So once you open the port to a specific protocol and ip address then any software can use it. Which can potentially be a security risk if the port is needed but a malicious program were to use it as well.
However if the ufw were capable of providing application level filtering of traffic it could really help to boost security of all systems with it installed, configured and running. It would as a result then harden the Ubuntu Linux even further than without. As well as provide even more information to those administering systems as connections for applications which are blocked would be logged.
So can the ufw software be updated in time for the release of 18.04 LTS? May be worth an exception by those responsible for project management.