Currently, tl-setup offers to open up these ports in the firewall: 22, 1010, 9000, 904 For a single server, this is too much: Port 9000 and 904 are only used internally, and port 1010 is also not necessary if you run the browser locally. I think this gives a somewhat bad impression that is not in line with our selling point "the only port you need is 22". I would prefer a more fine grained control, something like this: [X] 22 (SSH) [X] 1010 (TLS based Web Administration Interface) [ ] 9000 (Master service in a cluster configuration) [ ] 904 (Agent service in a cluster configuration)