, the GUI configuration does have firewall config, yes. But it's enormously easier to set up what I want — and maintain it — using Shorewall.
Thanks for the no-more tip, I'll give it a try.
, thanks for the link. I'll keep that for cert installation reference. Of course I can use a self-signed cert from my own CA, which my browser already trusts, since basically nobody outside my own network is ever going to see it anyway.