The firewall, and who may reach SSH
ufw or firewalld, whichever the box runs, with iptables and nftables read and judged behind them. Eight tabs: the verdict, what is reachable — every listening port judged against the rules, so a service open to the world is a finding and not a guess — the rules themselves folded so a v4 rule and its v6 twin are one line, what is open to the world by name, who may reach SSH, the defaults in words, who is knocking (refused connections folded by address), and the log.
One dialog covers a preset, a new rule, or the SSH question, and it asks it the way a person asks it: to whom. Allow and deny rows, denies written before allows, a preview of what will be written. And one invariant that cannot be argued with: the SSH port is allowed before the firewall is ever turned on, its rule cannot be removed while it is the only cover, and a rule that would deny your own address is refused — on screen, and again in Go before anything is written.











