If you want to run an E-smith 4.1.1 directly connected to the internet in Server only mode, do you need to modify it somehow to make it secure? (As it seems like the Firewall rules are disabled in Server-only mode)
What services should you disable, block etc? What poses security risks?
The only thing I would really need is apache for www, webmail and ssh for administration