Harden my pi running pihole? (install ufw)

No, firewalls don't do anything for localhost.

ah ok

Question:
As pihole on your network is behind your routers (SPI) firewall, what does it matter to have a firewall behind a firewall ?

IMO - Generally speaking, in today's threat and target rich environment - especially in the context of home network security remediation and hardening - the more options you have available to build in additional layers of protection, the better!

To answer your question more specifically: "what does it matter / what is the added value of having a firewall behind a firewall?"

Your router's existing firewall will provide connected devices (including your Pi-hole) some level of protection against threats originating from the WAN (the outside internet), sure...

BUT - what your router's existing firewall is going to be highly ineffective against are LATERAL ATTACKS (Lateral Movement Explained | What is Lateral Movement?) - that is - malicious traffic originating from inside your LAN - from an infected smartphone app or vulnerable packages bundled with the software / firmware of any connected SmartHome / IoT device for a couple of good examples...

While contemporary home network equipment has become somewhat better at providing the means to configure your home network in such a way as to better protect against lateral movement at the router level (such as the ability to configure isolated VLANs / subnets per device automatically as needed at connect time) - MOST home network equipment even today that your average home user will have the budget for do not provide such a high level of configurability, even some of the more expensive options on the market today even still lack those additional features, and even in the best of cases - where the options are there, still requires the user to have the knowledge base to configure and maintain them, and even then are still no magic bullet.

So, in summary, anywhere you can build in one more layer of protection into your home network, especially with a relatively low level of complexity, please take the opportunity!

The fantastic team of volunteer developers that have delivered us this equally fantastic Pi-hole framework have already delivered us such an amazing foundation to build each our own multi-layered security approach in to our networks - it's on us to make sure we take full advantage and leverage it for its complete vast potential!

Thanks Pi-hole Team! :blush: :100: :pray: :ok_hand: :technologist: :mechanical_arm:

2 Likes