Mistake 1
Binding the gateway too broadly
If your gateway is bound to 0.0.0.0 without a very clear reason, you are increasing your exposure surface immediately. Loopback by default is the sane choice. Use a controlled remote path like Tailscale if you actually need outside access.