So while we'll get round to better protecting services running on those ports we absolutely need, we can also create access controls using a basic firewall and, for that, let's consider two options:
This may be basic, but it works. Try a door and unless it's whitelisted, it won't budge.
The assumption here is that you either do not have a firewall, else that it needs re-addressing. For the former, we will install the package and, for both, we'll tune the ruleset.
Assume root privileges and list your current rules:
sudo -i
/sbin/iptables -L
If it looks like this, you have no rules:
Or if instead you receive an error like this, then the package isn't...