Skip to content
BotServBotServ
FirewallNetwork SecurityiptablesnftablesUFWLocal AISecurity

Firewall Basics for AI Systems

Firewall fundamentals for secure local AI operation. Ports, rules, zones and common mistakes to avoid.

S

schutzgeist

3 min read
Firewall Basics for AI Systems

Firewall Basics for AI Systems

What this article covers

  • What a firewall does and why it matters.
  • How to effectively manage ports and rules.
  • Common tools on Linux.
  • How to avoid typical mistakes.

Introduction: Firewall Basics for AI Systems

A firewall is your first line of defense against unwanted network traffic. It decides which connections reach your server and which get blocked. For AI systems, a firewall is especially critical because services like Ollama, Open WebUI, or vector databases should never be exposed to the open internet.

Even if you run your server on a local network, you need a firewall. It prevents services intended only for internal use from accidentally becoming visible to other networks.

Why do you need a firewall?

Without a firewall, your server responds to every request sent to an open port. Any reachable service becomes a potential attack target. A firewall shrinks your attack surface to only what’s necessary.

For AI systems, this means opening only the ports you need and keeping all other services accessible only locally or from specific networks.

How firewalls work

A firewall operates using rules. Each rule evaluates connections based on several criteria:

  • Source IP: Who is sending the request?
  • Destination IP: Which address is it going to?
  • Port: Which service is being accessed?
  • Protocol: TCP, UDP, or ICMP?
  • Direction: Inbound or outbound?

Rules are processed from top to bottom. When a rule matches, it gets applied. If none match, the default rule kicks in, which usually blocks the traffic.

Who should read this article?

  • Beginners setting up their first rules.
  • Home server operators securing their services.
  • Developers deploying AI systems in production.
  • Anyone who wants to understand network security better.

Key firewall concepts

  • Port: Address for a service on a machine.
  • TCP/UDP: Network protocols for data transmission.
  • DMZ: Demilitarized zone, a separate network segment for servers.
  • Stateful/Stateless: Stateful firewalls remember existing connections.
  • UFW: Uncomplicated Firewall, a straightforward interface for iptables.
  • nftables: Modern firewall framework in Linux.
  • Default-Deny: Block everything except what you explicitly allow.

Firewall rules in practice

Minimal AI server

A home server needs inbound SSH on port 22 and HTTPS on port 443. Ollama on port 11434 is accessible only internally. All other inbound ports are blocked.

Separating web UI and API

Open WebUI runs on port 8080 and is reachable only from your local network. External requests come through a reverse proxy on port 443.

Multiple network zones

Containers with databases and vector stores communicate only internally. The application is the only service exposed externally.

Common firewall pitfalls

  • Too many open ports: Every open port is a potential vulnerability.
  • Default-Allow: Allowing everything and selectively blocking is less secure.
  • Rules not tested: Misconfiguration can make services unreachable.
  • Unprotected SSH: Port 22 should only be reachable from trusted networks.
  • Container ports overlooked: Docker often exposes ports through the host firewall.

Cybersecurity fundamentals: Firewalls in the AI landscape

Important note

Firewalls are a cornerstone of IT security. On IRC-Security.de you’ll find extensive coverage of firewalls, AI hacking, AI protection measures, and more.

Further reading and firewall resources

FAQ: Firewall basics

Is a firewall enough on its own? No. It’s an important layer, but not a complete security solution. Updates, authentication, and solid configuration are equally important.

Should I open port 22 for SSH? Only from trusted networks, or combine it with additional measures like Fail2Ban and key-based authentication.

Which tool should I use? UFW is simple and sufficient for most servers. nftables offers more control. Proxmox and Docker have their own network rules.

Should I block outbound traffic too? Usually not necessary for home servers. In stricter environments, restrictive outbound rules can make sense.

What happens if my firewall blocks a service? You won’t be able to access that service. Test rules first in a safe environment and ensure you keep an alternative way in.

Sources and further reading

Summary: Firewall basics for AI systems

A firewall is one of the simplest and most effective security measures for local AI systems. It restricts incoming traffic to only the ports and protocols you need. Key practices include default-deny rules, clear rule definitions, restricting SSH access, and regularly reviewing your configuration. If you use Docker or other container platforms, pay special attention to their networking behavior.

Back to Blog
Share:

Related Posts