Network Security
Service Minimalism
Run as few network services on IGEL OS 12 as possible. Once an OS 12 endpoint is registered with your UMS, it exposes only a single service — the portmapper. Even that service may not be required and can be deactivated.
--> See: Disabling RPC Portmapper Service
Host-based Firewall with iptables
By default, no host-based firewall is active on IGEL OS 12. If you follow the Service Minimalism principle, you may not need one.
However, the Linux kernel included in IGEL OS 12 supports comprehensive firewall functionality that can be configured using the iptables or nftables command-line tools. You can deploy firewall rules to endpoints by configuring commands in:
System > System Customization > Custom Commands Base > Network > Initialization within a UMS Profile.