Controlling what reaches your server.
THE PRINCIPLE
Deny by default. Allow only what is needed.
WHAT TO ALLOW
Web traffic Remote access, ideally restricted to known addresses Mail, if you run it
WHAT TO DENY
Everything else, including database ports.
THE DATABASE POINT
A database should not be reachable from the internet.
An exposed database is among the most commonly exploited misconfigurations.
RESTRICTING REMOTE ACCESS BY ADDRESS
If you always connect from known locations, allow only those.
Considerably stronger than any other measure.
Keep a fallback route in case your address changes.
RATE LIMITING
Limiting connection attempts reduces automated attacks.
WHAT TO CHECK PERIODICALLY
What is actually listening on a network port.
Frequently something you installed and forgot.
AFTER ANY FIREWALL CHANGE
Verify you can still connect before closing your session.