Skip to content

Is it secure to expose port 9001 directly to the public internet? #12763

Answered by Nick-Portainer
itning asked this question in Help
Discussion options

You must be logged in to vote

Hi @itning, the short answer is no but it can be more complex than this. Here is a blog post our CEO Neil created around this - https://www.portainer.io/blog/should-you-expose-portainer-or-agent-to-the-internet It's worth a read.

The standard Agent is designed for use WITHIN YOUR LAN/WAN, and the Edge Agent is designed to manage container environments connected to the public internet. If you are using our standard agent, and you have exposed it to the internet (by publishing port 9001 publically), then might we suggest that you rethink this strategy. If nothing else, you should have a firewall ACL in place that only allows access to port 9001 from trusted IPs (namely, the public IP of yo…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Nick-Portainer
Comment options

Answer selected by itning
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
None yet
2 participants