- Enable ufw and by default deny incoming traffic - in other roles: if ufw (role) is enabled, then allow necessary ports