Re: Introductory reading on firewall/iptables/etc for new Debian user?

2013-04-23 Thread Lisi Reisz
On Tuesday 23 April 2013 16:06:18 Richard Owlett wrote: > I want to prevent an app from > deciding to update on its schedule not mine. I don't have any applications set to update automatically. That is the simple solution to that problem! Lisi -- To UNSUBSCRIBE, email to debian-user-requ...

Re: Introductory reading on firewall/iptables/etc for new Debian user?

2013-04-23 Thread Lisi Reisz
On Tuesday 23 April 2013 15:43:23 Dan Ritter wrote: > On Tue, Apr 23, 2013 at 09:28:17AM -0500, Richard Owlett wrote: > > I will be using email, Usenet, browser and occasionally file > > downloading. > > Nothing on my system should look/act like a server. > > I want all programs to access the inter

Re: Introductory reading on firewall/iptables/etc for new Debian user?

2013-04-23 Thread Jochen Spieker
t;No >Always YES >Ask each occurrence This sounds like you want some kind of "personal firewall" like it is (or was) common on Windows. What problem do you want to solve? The security gain of this approach is very small. The nearest solution is to setup iptables to re

Re: Introductory reading on firewall/iptables/etc for new Debian user?

2013-04-23 Thread Richard Owlett
Dan Ritter wrote: On Tue, Apr 23, 2013 at 09:28:17AM -0500, Richard Owlett wrote: I will be using email, Usenet, browser and occasionally file downloading. Nothing on my system should look/act like a server. I want all programs to access the internet after explicitly asking for permission. The r

Re: Introductory reading on firewall/iptables/etc for new Debian user?

2013-04-23 Thread Dan Ritter
On Tue, Apr 23, 2013 at 09:28:17AM -0500, Richard Owlett wrote: > I will be using email, Usenet, browser and occasionally file > downloading. > Nothing on my system should look/act like a server. > I want all programs to access the internet after explicitly asking > for permission. > The response t

Introductory reading on firewall/iptables/etc for new Debian user?

2013-04-23 Thread Richard Owlett
I will be using email, Usenet, browser and occasionally file downloading. Nothing on my system should look/act like a server. I want all programs to access the internet after explicitly asking for permission. The response to the request may be: No Always YES Ask each occurrence --

Re: multiple nic/IP in firewall

2013-01-30 Thread Roberto Scattini
On Sun, Jan 27, 2013 at 10:51 AM, Pascal Hambourg wrote: > Roberto Scattini a écrit : > > > > i just cant make it work. > > all my outgoing packets keep going through the default gateway (even if > > they have the correct IP address, from the other nic...). > > > > i think i need an explanation...

Re: multiple nic/IP in firewall

2013-01-27 Thread Pascal Hambourg
Roberto Scattini a écrit : > > i just cant make it work. > all my outgoing packets keep going through the default gateway (even if > they have the correct IP address, from the other nic...). > > i think i need an explanation... because i cant undestand how does the > routing tables know that a p

Re: multiple nic/IP in firewall

2013-01-24 Thread Roberto Scattini
On Wed, Jan 23, 2013 at 9:45 PM, Tom Furie wrote: > On Tue, Jan 22, 2013 at 07:54:25PM -0300, Roberto Scattini wrote: > > > ~# route -n > > Kernel IP routing table > > Destination Gateway Genmask Flags Metric RefUse > > Iface > > XX.220.XX.176 0.0.0.0 255.255.255.

Re: multiple nic/IP in firewall

2013-01-23 Thread Tom Furie
On Tue, Jan 22, 2013 at 07:54:25PM -0300, Roberto Scattini wrote: > ~# route -n > Kernel IP routing table > Destination Gateway Genmask Flags Metric RefUse > Iface > XX.220.XX.176 0.0.0.0 255.255.255.255 UH0 00 eth3 > YY.20.YY.0 0.0.0.0

Re: multiple nic/IP in firewall

2013-01-23 Thread Roberto Scattini
On Wed, Jan 23, 2013 at 8:00 PM, Tom Furie wrote: > > > Possibly a silly question, but something you might have overloooked - > what does your nat table look like? Are you forwarding the traffic from > eth4 to your web server? > > Cheers, > Tom > tom, yes, i have the same rules that i have for m

Re: multiple nic/IP in firewall

2013-01-23 Thread Tom Furie
On Wed, Jan 23, 2013 at 05:47:02PM -0300, Roberto Scattini wrote: > i also tried a different approach, found somewhere with google, that is > more in line with my understanding of the problem. > basically, it marks the packets so they can be routed back to the same nic > they came in: > > ip rout

Re: multiple nic/IP in firewall

2013-01-23 Thread Roberto Scattini
hi again, Dňa Wed, 23 Jan 2013 00:07:51 -0300 "Carlos Miranda Molina > (Mstaaravin)" napísal: > > > :~# ip route add default scope global nexthop via XX.220.XX.177 dev > > eth3 weight 1 nexthop via YY.20.YY.Y dev eth4 weight 1 > > :~# ip route add '127.0.0.0/8' dev lo table T1 > > :~# ip route ad

Re: multiple nic/IP in firewall

2013-01-23 Thread Slavko
Hi, in English, please! Dňa Wed, 23 Jan 2013 00:07:51 -0300 "Carlos Miranda Molina (Mstaaravin)" napísal: > On Tue, Jan 22, 2013 at 10:42 PM, Roberto Scattini < > roberto.scatt...@gmail.com> wrote: > > > 1. the second interface, in on same subnet as the first > > interface? no, they are co

Re: multiple nic/IP in firewall

2013-01-22 Thread Carlos Miranda Molina (Mstaaravin)
On Tue, Jan 22, 2013 at 10:42 PM, Roberto Scattini < roberto.scatt...@gmail.com> wrote: > 1. the second interface, in on same subnet as the first interface? > no, they are completely different > > >> 2. the gateway for second interface is different as the first >> interface? >> > yeah, bot

Re: multiple nic/IP in firewall

2013-01-22 Thread Roberto Scattini
On Tue, Jan 22, 2013 at 9:46 PM, Carlos Miranda Molina (Mstaaravin) < mstaara...@gmail.com> wrote: > >> > 1. the second interface, in on same subnet as the first interface? > no, they are completely different > 2. the gateway for second interface is different as the first > interface? >

Re: Outgoing firewall and CNAMES

2012-09-16 Thread Tom Grace
On 12/09/12 17:59, Lists wrote: > I use an outgoing policy of deny on webservers, and allow explicitely > what I need them to connect to. This has never posed a problem, until > today. I need to allow a website to pull in a feed from another site, > hosted on amazon's elastic cloud thingy. The p

Outgoing firewall and CNAMES

2012-09-12 Thread Lists
Hi guys, I use an outgoing policy of deny on webservers, and allow explicitely what I need them to connect to. This has never posed a problem, until today. I need to allow a website to pull in a feed from another site, hosted on amazon's elastic cloud thingy. The problem is, the DNS name i

Re: firewall

2012-07-14 Thread Joel Roth
On Wed, Jul 04, 2012 at 11:19:06AM +0800, lina wrote: > Hi, > > I don't know which firewall (http://wiki.debian.org/Firewalls) I should > choose. > > Thanks ahead for recommendation, and it will be very nice if you tell > me why you recommend this one. >From o

Re: firewall

2012-07-10 Thread Chris Bannister
On Wed, Jul 04, 2012 at 11:19:06AM +0800, lina wrote: > Hi, > > I don't know which firewall (http://wiki.debian.org/Firewalls) I should > choose. > > Thanks ahead for recommendation, and it will be very nice if you tell > me why you recommend this one. Have a

Re: firewall

2012-07-06 Thread Jon Dowland
On Fri, Jul 06, 2012 at 05:39:47PM +0300, Andrei POPESCU wrote: > On Mi, 04 iul 12, 15:16:10, Jon Dowland wrote: > > > > Except on Debian you are required to do a fair amount of work to make > > your rules persistent across reboots and ensure you get ordering right > > to not lock yourself out of

Re: firewall

2012-07-06 Thread Andrei POPESCU
On Mi, 04 iul 12, 15:16:10, Jon Dowland wrote: > > Except on Debian you are required to do a fair amount of work to make > your rules persistent across reboots and ensure you get ordering right > to not lock yourself out of the box (if remote): all problems that > do not exist if you install and u

Re: firewall

2012-07-05 Thread Eike Lantzsch
>>> mailto:ralf.mard...@alice-dsl.net>> wrote: > >>>> On Wed, 2012-07-04 at 11:19 +0800, lina wrote: [snip Lina's request for recommendation on firewalls] [snip Ralf Mardorf's dry answer] [snip Brad Alexander's disagreement] [snip Anthony Campbell's anec

Re: firewall

2012-07-05 Thread Doug
know which firewall (http://wiki.debian.org/Firewalls) I should choose. Thanks ahead for recommendation, and it will be very nice if you tell me why you recommend this one. To answer drily: Test them and report what firewall does protect you the best against no attacks. Linux for home usage was saf

Re: firewall

2012-07-05 Thread Jon Dowland
Your reply (the text/plain portion) was completely illegible I'm afraid. Please refrain from sending HTML mail. -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/201207

Re: firewall

2012-07-05 Thread Jon Dowland
On Wed, Jul 04, 2012 at 04:52:10PM -0400, Brad Alexander wrote: > Excellent points, Joe. In addition, Windows was designed from the ground up > as a single-user operating system, which means that all of the files on a > system were accessible by the user. This is not true for the NT-based Windows

Re: firewall

2012-07-05 Thread Atıf CEYLAN
On 2012-07-05 10:05, Anthony Campbell wrote: > On 04 Jul 2012, Brad Alexander wrote: > >> On Wed, Jul 4, 2012 at 2:15 AM, Ralf Mardorf wrote: >> >>> On Wed, 2012-07-04 at 11:19 +0800, lina wrote: >>> >>>> Hi, I don't know which fir

Re: firewall

2012-07-05 Thread Anthony Campbell
On 04 Jul 2012, Brad Alexander wrote: > On Wed, Jul 4, 2012 at 2:15 AM, Ralf Mardorf > wrote: > > On Wed, 2012-07-04 at 11:19 +0800, lina wrote: > >> Hi, > >> > >> I don't know which firewall (http://wiki.debian.org/Firewalls) I should > >> c

Re: firewall

2012-07-05 Thread Weaver
> On Wed, Jul 4, 2012 at 3:38 AM, Ralf Mardorf > wrote: >> >> *chuckle* A trillion years ago I used a firewall myself. "Ports" are an >> issue, I wasn't able to down- or upload by ftp. BUT, How many serious >> attacks did you notice around the l

Re: firewall

2012-07-04 Thread lina
On Thu, Jul 5, 2012 at 5:31 AM, Brian wrote: > On Wed 04 Jul 2012 at 11:19:06 +0800, lina wrote: > >> I don't know which firewall (http://wiki.debian.org/Firewalls) I >> should choose. >> >> Thanks ahead for recommendation, and it will be very nice if you te

Re: firewall

2012-07-04 Thread Brad Alexander
On Wed, Jul 4, 2012 at 6:04 PM, Brian wrote: > A commonly used phrase - military in origin, I imagine. One day I must > investigate how a firewall can protect my mail server. Until then I will > just continue to accept connections from anywhere. I will give you an example of t

Re: firewall

2012-07-04 Thread Brian
On Wed 04 Jul 2012 at 08:21:10 -0400, Eike Lantzsch wrote: > OK, I see that this might be flamebait ... > > On Tuesday 03 July 2012 23:19:06 lina wrote: > > Hi, > > > > I don't know which firewall (http://wiki.debian.org/Firewalls) I should > > choose. &g

Re: firewall

2012-07-04 Thread Brian
On Wed 04 Jul 2012 at 12:14:29 -0400, Brad Alexander wrote: > On Wed, Jul 4, 2012 at 2:15 AM, Ralf Mardorf > wrote: > > > > To answer drily: Test them and report what firewall does protect you the > > best against no attacks. Linux for home usage was safe, is safe, wil

Re: firewall

2012-07-04 Thread Brian
On Wed 04 Jul 2012 at 11:19:06 +0800, lina wrote: > I don't know which firewall (http://wiki.debian.org/Firewalls) I > should choose. > > Thanks ahead for recommendation, and it will be very nice if you tell > me why you recommend this one. You can either manipulate net

Re: firewall

2012-07-04 Thread Tom H
On Wed, Jul 4, 2012 at 3:38 AM, Ralf Mardorf wrote: > > *chuckle* A trillion years ago I used a firewall myself. "Ports" are an > issue, I wasn't able to down- or upload by ftp. BUT, How many serious > attacks did you notice around the last 30 days? Your aversion to s

Re: firewall

2012-07-04 Thread Tom H
On Wed, Jul 4, 2012 at 4:04 AM, Joe wrote: > > Most ports can be closed by configuration, even the infamous portmap > can be limited to localhost if you're not using it externally e.g. for > NIS or NFS. If you have a standalone Linux machine in a foreign > network, pretty much everything can be cl

Re: firewall

2012-07-04 Thread Adrian Fita
On 04/07/12 10:31, Mika Suomalainen wrote: > On 04.07.2012 06:19, lina wrote: >> >> I don't know which firewall (http://wiki.debian.org/Firewalls) I >> should choose. >> >> [...] >> > I recommend UFW. It's simple to use and does everything what f

Re: firewall

2012-07-04 Thread Brad Alexander
On Wed, Jul 4, 2012 at 3:46 PM, Joe wrote: > On Wed, 4 Jul 2012 18:11:14 +0100 > Lisi wrote: > >> On Wednesday 04 July 2012 17:14:29 Brad Alexander wrote: >> > The third reason we >> > are not in the same boat as windows is that we have a much smaller >> > attack surface than Windows. Windows sti

Re: firewall

2012-07-04 Thread Joe
On Wed, 4 Jul 2012 18:11:14 +0100 Lisi wrote: > On Wednesday 04 July 2012 17:14:29 Brad Alexander wrote: > > The third reason we > > are not in the same boat as windows is that we have a much smaller > > attack surface than Windows. Windows still has over 90% penetration > > on the desktop, There

Re: firewall

2012-07-04 Thread Lisi
On Wednesday 04 July 2012 17:14:29 Brad Alexander wrote: > The third reason we > are not in the same boat as windows is that we have a much smaller > attack surface than Windows. Windows still has over 90% penetration on > the desktop, Therefore, they are the low hanging fruit. How, then, do you e

Re: firewall

2012-07-04 Thread Brad Alexander
On Wed, Jul 4, 2012 at 2:15 AM, Ralf Mardorf wrote: > On Wed, 2012-07-04 at 11:19 +0800, lina wrote: >> Hi, >> >> I don't know which firewall (http://wiki.debian.org/Firewalls) I should >> choose. >> >> Thanks ahead for recommendation, and it will be v

Re: firewall

2012-07-04 Thread lina
P.S. Your guys are great. Sometimes even I didn't reply item by item, or thanks one by one, but I read every sentences in the emails. Many times read more than once. So please kindly realize that your suggestions are very valuable and highly appreciated (most time silently). BTW, I didn't realize t

Re: firewall

2012-07-04 Thread lina
Hi, Following the instructions from http://wiki.debian.org/iptables I am kinda of "running" the iptables now? (perhaps I understand wrong. welcome correction.) One thing a bit unexpected (to me) is that there are continuously rolling info as following: Jul 4 22:18:07 Debian dhclient: DHCPREQU

Re: firewall

2012-07-04 Thread Jon Dowland
On Wed, Jul 04, 2012 at 10:53:00AM +0300, Lars Noodén wrote: > On 7/4/12 10:46 AM, Muhammad Yousuf Khan wrote: > > Web base Firewall (IPCOP) very powerful with the addon called BOT > > (block out traffice) base on IPtables. > > In some ways it's easier just to work with

Re: firewall

2012-07-04 Thread Eike Lantzsch
OK, I see that this might be flamebait ... On Tuesday 03 July 2012 23:19:06 lina wrote: > Hi, > > I don't know which firewall (http://wiki.debian.org/Firewalls) I should > choose. > > Thanks ahead for recommendation, and it will be very nice if you tell > me

Re: firewall

2012-07-04 Thread Muhammad Yousuf Khan
On Wed, Jul 4, 2012 at 1:16 PM, Ralf Mardorf wrote: > On Wed, 2012-07-04 at 12:46 +0500, Muhammad Yousuf Khan wrote: >> Web base Firewall (IPCOP) very powerful with the addon called BOT >> (block out traffice) base on IPtables. > > I don't care, but I certain that I kno

Re: firewall

2012-07-04 Thread Atıf CEYLAN
On Wed, 2012-07-04 at 11:19 +0800, lina wrote: > Hi, > > I don't know which firewall (http://wiki.debian.org/Firewalls) I should > choose. > > Thanks ahead for recommendation, and it will be very nice if you tell > me why you recommend this one. > > Best regard

Re: firewall

2012-07-04 Thread Weaver
> Hi, > > I don't know which firewall (http://wiki.debian.org/Firewalls) I should > choose. APF (Advanced Policy Firewall) > > Thanks ahead for recommendation, and it will be very nice if you tell > me why you recommend this one. Easy to configure and comprehensivel

Re: firewall

2012-07-04 Thread Ralf Mardorf
On Wed, 2012-07-04 at 12:46 +0500, Muhammad Yousuf Khan wrote: > Web base Firewall (IPCOP) very powerful with the addon called BOT > (block out traffice) base on IPtables. I don't care, but I certain that I know some guys (no women) how recommend IPCOP too, for good reasons. At least f

Re: firewall

2012-07-04 Thread lina
Thanks all. Actually I even don't know how to check where there was/is attach or not. I am looking for a firewall is mainly to have some sense of guarantee, otherwise I will definitely freak out in front of attack. I will start learning something about iptables. Just know so little ^_^ T

Re: firewall

2012-07-04 Thread Muhammad Yousuf Khan
On Wed, Jul 4, 2012 at 12:53 PM, Lars Noodén wrote: > On 7/4/12 10:46 AM, Muhammad Yousuf Khan wrote: >> Web base Firewall (IPCOP) very powerful with the addon called BOT >> (block out traffice) base on IPtables. > > In some ways it's easier just to work with IPtables di

Re: firewall

2012-07-04 Thread Joe
portmap can be limited to localhost if you're not using it externally e.g. for NIS or NFS. If you have a standalone Linux machine in a foreign network, pretty much everything can be closed. I'd have thought most of the simple firewall frontends would do what you need. If they are simple to

Re: firewall

2012-07-04 Thread Lars Noodén
On 7/4/12 10:46 AM, Muhammad Yousuf Khan wrote: > Web base Firewall (IPCOP) very powerful with the addon called BOT > (block out traffice) base on IPtables. In some ways it's easier just to work with IPtables directly. Regards, /Lars -- To UNSUBSCRIBE, email to debia

Re: firewall

2012-07-04 Thread Muhammad Yousuf Khan
Web base Firewall (IPCOP) very powerful with the addon called BOT (block out traffice) base on IPtables. On Wed, Jul 4, 2012 at 12:38 PM, Ralf Mardorf wrote: > On Wed, 2012-07-04 at 15:04 +0800, lina wrote: >> On 4 Jul, 2012, at 14:15, Ralf Mardorf wrote: >> >> > On

Re: firewall

2012-07-04 Thread Ralf Mardorf
On Wed, 2012-07-04 at 15:04 +0800, lina wrote: > On 4 Jul, 2012, at 14:15, Ralf Mardorf wrote: > > > On Wed, 2012-07-04 at 11:19 +0800, lina wrote: > >> Hi, > >> > >> I don't know which firewall (http://wiki.debian.org/Firewalls) I should > >&g

Re: firewall

2012-07-04 Thread Mika Suomalainen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, On 04.07.2012 06:19, lina wrote: > Hi, > > I don't know which firewall (http://wiki.debian.org/Firewalls) I > should choose. > > Thanks ahead for recommendation, and it will be very nice if you > tell me why you rec

Re: firewall

2012-07-04 Thread lina
On 4 Jul, 2012, at 14:15, Ralf Mardorf wrote: > On Wed, 2012-07-04 at 11:19 +0800, lina wrote: >> Hi, >> >> I don't know which firewall (http://wiki.debian.org/Firewalls) I should >> choose. >> >> Thanks ahead for recommendation, and it will be v

Re: firewall

2012-07-03 Thread Ralf Mardorf
On Wed, 2012-07-04 at 11:19 +0800, lina wrote: > Hi, > > I don't know which firewall (http://wiki.debian.org/Firewalls) I should > choose. > > Thanks ahead for recommendation, and it will be very nice if you tell > me why you recommend this one. To answer drily:

firewall

2012-07-03 Thread lina
Hi, I don't know which firewall (http://wiki.debian.org/Firewalls) I should choose. Thanks ahead for recommendation, and it will be very nice if you tell me why you recommend this one. Best regards, -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org with a subje

firewall time_wait jump after ssl security update

2012-05-01 Thread Bonno Bloksma
big jump in the TIME_WAIT in my munin firewall graphs. See https://intranet.tio.nl/Documenten/helpdesk/temp/fw_conntrack-week-linein.png Any idea what is going on and what I need to look at? Bonno Bloksma senior systeembeheerder tio university of applied sciences netherlands -- To UNSUBSCRIBE

Re: simple stand-alone firewall

2012-04-02 Thread Arnt Karlsen
On Fri, 30 Mar 2012 22:48:18 +0400, wlan wrote in message : > 2012/3/30 Russell L. Harris > > > * Russell L. Harris [120324 07:15]: > > > >From the standpoint of protection of a LAN (two or three > > > >machines) for > > > a home or home off

Re: simple stand-alone firewall

2012-03-30 Thread wlan
I think netfilter are better firewall, you can read documentation from iptables. It's really cool. =) 2012/3/30 Russell L. Harris > * Russell L. Harris [120324 07:15]: > > >From the standpoint of protection of a LAN (two or three machines) for > > a home or home office.

Re: simple stand-alone firewall

2012-03-30 Thread Russell L. Harris
* Russell L. Harris [120324 07:15]: > >From the standpoint of protection of a LAN (two or three machines) for > a home or home office... ... > Is there a good firewall application in Debian which provides a secure > default configuration? Or must I learn how to configure a fir

Re: simple stand-alone firewall

2012-03-27 Thread Curt
On 2012-03-24, Charles Kroeger wrote: > > You won't get a 'stealth' rating at grc. Shorewall seems to leave port 0 That's all hooey anyway, that "stealth" business, as if you're some kind of combat aircraft over an Iranian nuclear installation or something, prospect which must be attractive to th

Re: simple stand-alone firewall

2012-03-26 Thread Andrei POPESCU
On Sb, 24 mar 12, 11:16:08, Charles Kroeger wrote: > > You won't get a 'stealth' rating at grc. Shorewall seems to leave port 0 > visible but closed. I don't know why this is but would be interested to know > if someone on this list knew the reason. Port 0? I haven't used Shorewall in a while, bu

Re: simple stand-alone firewall

2012-03-26 Thread Celejar
On Sat, 24 Mar 2012 12:17:50 + Chris Davies wrote: > Russell L. Harris wrote: > > From the standpoint of protection of a LAN (two or three machines) > > for a home or home office, how effective is a firmware-based > > firewall/router in comparison with a softw

Re: simple stand-alone firewall

2012-03-24 Thread Steven Jan Springl
What is the deal with port 0? I have just tried grc, and my Shorewall firewall gets a 'stealth' rating. Steven. -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/201203242218.08365.ste...@springl.ukfsn.org

Re: simple stand-alone firewall

2012-03-24 Thread Charles Kroeger
>Is there a good firewall application in Debian which provides a secure >default configuration? Or must I learn how to configure a firewall? The package: 'arno-iptables-firewall' will do that. You will have to tell it how you're connecting (e.g. eth0) but after that it will

Re: simple stand-alone firewall

2012-03-24 Thread Chris Davies
Russell L. Harris wrote: > From the standpoint of protection of a LAN (two or three machines) > for a home or home office, how effective is a firmware-based > firewall/router in comparison with a software-based stand-alone > firewall/router? Is either significantly better th

Re: simple stand-alone firewall

2012-03-24 Thread green
Russell L. Harris wrote at 2012-03-24 02:02 -0500: > Is there a good firewall application in Debian which provides a secure > default configuration? Or must I learn how to configure a firewall? Hopefully you are able to find something simple to use, but if you do learn how to confi

Re: simple stand-alone firewall

2012-03-24 Thread Mika Suomalainen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I use UFW as firewall on all computers at home. It's very easy to configure. UFW (package ufw) can be found from Debian repositories. For documentation see https://help.ubuntu.com/community/UFW . There is also graphical user interface c

Re: simple stand-alone firewall

2012-03-24 Thread Camaleón
On Sat, 24 Mar 2012 07:02:42 +, Russell L. Harris wrote: > From the standpoint of protection of a LAN (two or three machines) for > a home or home office, how effective is a firmware-based firewall/router > in comparison with a software-based stand-alone firewall/router? I'

simple stand-alone firewall

2012-03-24 Thread Russell L. Harris
>From the standpoint of protection of a LAN (two or three machines) for a home or home office, how effective is a firmware-based firewall/router in comparison with a software-based stand-alone firewall/router? Is either significantly better than the other? I am thinking in terms of devoting

Re: Setup a firewall/gateway/server

2012-01-14 Thread Csanyi Pal
Csanyi Pal writes: > Andrei Popescu writes: > >> On Sb, 14 ian 12, 20:18:31, Csanyi Pal wrote: > Now, after I rebooted with my headless system, I can to SSH to it, and > that is the good news. > > The bad news is that that I can't browse the Internet from the LAN > behind the headless machine

Re: Setup a firewall/gateway/server

2012-01-14 Thread Csanyi Pal
Andrei Popescu writes: > On Sb, 14 ian 12, 20:18:31, Csanyi Pal wrote: >> >> I must to reinstall instead of fixing the problem because this is a >> headless PC Box, so if I make a mistake then it can be happen that that >> I can't to SSH into that system again to fix the problem this way. > > Th

Re: Setup a firewall/gateway/server

2012-01-14 Thread Andrei Popescu
On Sb, 14 ian 12, 20:18:31, Csanyi Pal wrote: > > I must to reinstall instead of fixing the problem because this is a > headless PC Box, so if I make a mistake then it can be happen that that > I can't to SSH into that system again to fix the problem this way. There is always a way: rescue disk w

Re: Setup a firewall/gateway/server

2012-01-14 Thread Csanyi Pal
t; IP_FORWARDING=Yes >> nano /etc/shorewall/masq >> eth0192.168.10.0/24 >> nano /etc/shorewall/interfaces >> net eth0 detect blacklist,dhcp >> loc eth1detect dhcp >> >> nano /etc/shorewall/zones >&

Re: Setup a firewall/gateway/server

2012-01-14 Thread Andrei Popescu
2.168.10.0 (not 192.168.10.1). > nano /etc/shorewall/interfaces > net eth0detect blacklist,dhcp > loc eth1detect dhcp > > nano /etc/shorewall/zones > fw firewall > net ipv4 > loc ipv4 > > nano /etc/shorewall/

Re: Setup a firewall/gateway/server

2012-01-14 Thread Csanyi Pal
printk = 3 4 1 3 net.ipv4.ip_forward = 1 /etc/init.d/procps restart nano /etc/shorewall/shorewall.conf IP_FORWARDING=Yes nano /etc/shorewall/masq eth0192.168.10.1/24 nano /etc/shorewall/interfaces net eth0detect blacklist,dhcp loc eth1detect d

Re: Setup a firewall/gateway/server

2012-01-13 Thread Pascal Hambourg
Hello, Csanyi Pal a écrit : > > iface eth1 inet static > address 192.168.10.1 > netmask 255.255.255.0 > network 192.168.10.0 > broadcast 192.168.10.255 This line is wrong : > gateway 192.168.10.1 A host cannot be its own gateway. Also there can be only one default gateway, a

Re: Setup a firewall/gateway/server

2012-01-13 Thread Bob Proulx
Csanyi Pal wrote: > I want to setup my headless pc box on which run a Debian Squeeze system > for firewall/gateway/server for my home LAN. Sounds good. > What I want is to protect my LAN and to get a web server that is > reachable from the Internet and from LAN too. Sure. >

Re: Setup a firewall/gateway/server

2012-01-13 Thread Andrei Popescu
On Vi, 13 ian 12, 22:04:02, Csanyi Pal wrote: > > I want to use Shorewall as firewall manager and apache2 as a webserver. ... > IP Forwarding: > cat /proc/sys/net/ipv4/ip_forward > 1 > > but this setup doesn't work yet. Why? No idea, never got it to work either, bu

Setup a firewall/gateway/server

2012-01-13 Thread Csanyi Pal
Hi, I want to setup my headless pc box on which run a Debian Squeeze system for firewall/gateway/server for my home LAN. What I want is to protect my LAN and to get a web server that is reachable from the Internet and from LAN too. I want to use Shorewall as firewall manager and apache2 as a

Bridged firewall, port flapping

2011-10-31 Thread Edward Morbius
We run a small set of web infrastructure with the following configuration: - Upstream routre - Cisco Catalyst 2960G switch segmented into two vlans. - Pair of Debian boxes with a transparent bridging firewall comprising eth1 and eth2. These implement the physdev kernel module and

Re: Firewall Setup

2011-10-26 Thread Andrei Popescu
hives: the default shorewall.conf has ADMINISABSENTMINDED=Yes which means it won't cut any *existing* (ssh) connections, even if the new rule(s) would not allow them. This allows one to changes the firewall and still fix things from the existing session. It doesn't help much if you

Re: corporate firewall from an end user prospective

2011-09-09 Thread Bob Proulx
T o n g wrote: > The place that I work now block standard outbound ssh (and ftp) port > connections. I'm wondering, for a "standard" corporate firewall practice, > do they selectively block outbound ports, or do they selectively open > them. > > From an end u

Re: corporate firewall from an end user prospective

2011-09-08 Thread Juan Sierra Pons
6E66 E934 3406 A110 F4FE -- 2011/9/9 T o n g : > Hi, > > The place that I work now block standard outbound ssh (and ftp) port > connections. I'm wondering, for a "standard" corporate firewall practice, > do they selectively bl

Re: Firewall Setup

2011-08-02 Thread Bob Proulx
Paul Stuffins wrote: > My setup really only needs to allow access, from the internet to the server, > on ports 80 and 443, for Apache, 6, for ssh and 3306, for MySQL along > with access from the server to the Debian repos and 3306, I have a couple > database servers that I manage from one centr

Re: Firewall Setup

2011-08-02 Thread mark
On Monday 01 August 2011 8:08:00 pm Scott Ferguson wrote: > > If you're not comfortable just using SSH to push across rulesets > created using Guarddog (my choice), then you "might" consider using > (the non-Debian) Webmin/Usermin/Virtualmin:- > http://www.webmin.com/firewall.html > http://prdownlo

Re: Firewall Setup

2011-08-02 Thread Paul Stuffins
ons of a front end, either one that I can > > run via an Apache VirtualHost, obviously on a secured and locked down > > VirtualHost so that only I can access it, or via SSH. > > There is a good set of firewall/iptables front-ends at debian wiki: > > http://wiki.debian.org/Fi

Re: Firewall Setup

2011-08-02 Thread Camaleón
obviously on a secured and locked down > VirtualHost so that only I can access it, or via SSH. There is a good set of firewall/iptables front-ends at debian wiki: http://wiki.debian.org/Firewalls Greetings, -- Camaleón -- To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org

Re: Firewall Setup

2011-08-02 Thread Jerome BENOIT
quid firehole ? On 02/08/11 09:04, Jude DaShiell wrote: Why not check out arnos-iptables-firewall? On Tue, 2 Aug 2011, Alan Chandler wrote: On 01/08/11 21:56, Paul Stuffins wrote: Hi Guys, I am trying to set iptables up, but am getting into a right mess editing the rules direct in the init

Re: Firewall Setup

2011-08-02 Thread Jude DaShiell
Why not check out arnos-iptables-firewall? On Tue, 2 Aug 2011, Alan Chandler wrote: > On 01/08/11 21:56, Paul Stuffins wrote: > > Hi Guys, > > > > I am trying to set iptables up, but am getting into a right mess editing > > the rules direct in the init scrip

Re: Firewall Setup

2011-08-01 Thread Alan Chandler
down VirtualHost so that only I can access it, or via SSH. --Paul I am not sure I understand exactly what you mean, but this is my set of firewall rules which I reference in /etc/network/interfaces/pre-up. They are stored in file /etc/firewall Unlike the other replies I hand crafted these

Re: Firewall Setup

2011-08-01 Thread Bob Proulx
Csanyi Pal wrote: > Paul Stuffins writes: > > What are peoples recommendations of a front end, either one that I can > > run via an Apache VirtualHost, obviously on a secured and locked down > > VirtualHost so that only I can access it, or via SSH. > > I'm usin

Re: Firewall Setup

2011-08-01 Thread Csanyi Pal
Paul Stuffins writes: > What are peoples recommendations of a front end, either one that I can > run via an Apache VirtualHost, obviously on a secured and locked down > VirtualHost so that only I can access it, or via SSH. I'm using shorewall to setup my firewall. -- Rega

Re: Firewall Setup

2011-08-01 Thread Scott Ferguson
On 02/08/11 06:56, Paul Stuffins wrote: Hi Guys, I am trying to set iptables up, but am getting into a right mess editing the rules direct in the init script. What are peoples recommendations of a front end, either one that I can run via an Apache VirtualHost, obviously on a secured and locked

Re: Firewall Setup

2011-08-01 Thread Glenn English
On Aug 1, 2011, at 2:56 PM, Paul Stuffins wrote: > I am trying to set iptables up, but am getting into a right mess editing the > rules direct in the init script. > > What are peoples recommendations of a front end, either one that I can run > via an Apache VirtualHost, obviously on a secured a

Firewall Setup

2011-08-01 Thread Paul Stuffins
Hi Guys, I am trying to set iptables up, but am getting into a right mess editing the rules direct in the init script. What are peoples recommendations of a front end, either one that I can run via an Apache VirtualHost, obviously on a secured and locked down VirtualHost so that only I can access

Re: firewall?

2011-07-20 Thread hadi motamedi
On 7/20/11, Regid Ichira wrote: > hadi motamedi gmail.com> writes: > >> - Add the following line to /etc/sysconfig/iptables >> -A RH-Firewall-1-INPUT -p udp -m udp --dport 53 -j ACCEPT >> Then issue: >> #service iptables restart >> I tried for it and now t

<    1   2   3   4   5   6   7   8   9   10   >