Also, think really hard about what you need running, and what ports you
enable. In most cases, all you need is ssh. After that you should
configure ssh to not allow root logins, and even better, not allow passwords
(only use keys).
This gives some good food for thought...Jim touched on it
too.
Fact of the matter is that you can have the best firewall
software in the world running restrictive rules and still get hacked
if you allow connections to and run a vunerable server. And it looks
like RedHat 9 has plenty of security updates for holes discovered
after the RH9 release...looks like about 35:
https://rhn.redhat.com/errata/rh9-errata-security.html
Cablemodem, DSL, and other always-on broadband subnets are
constantly scanned for new vaunerable machines and then automatically
attacked en masse by scripts that often continue the hunt once they
infect new hosts. Its not all that uncommon to see large collections
of machines under the control of one 13 year old kid in his/her
basement.
This is the downside to Linux. Gotta lock it up solid or keep on
top of all the updates. The only way to really run a firewall
perfectly securely is to halt the system after it boots. It'll keep
passing traffic and following the firewall rules, but there won't be
enough of an active system to really hack.
Pkcp
