Hi all, I’m a new users of Trisquel, and I’d like to give it a thorough tryout — I do like it a lot so far. My question is about firewalls and related security items — I’ve done some research and now I have specific questions.
First, I’ve read on the Trisquel forum that gufw (which is a GUI front-end to ufw, which is a front-end to iptables) is a popular and possibly even recommended “firewall” for Linux. Now, I had recently been using Debian, and after merely installing and enabling ufw, I listed out the output of “iptables -L” and posted it to the debian-user mailing list, asking whether this set of rules appeared to provide basic, block-all-incoming-connection protection. However, after at least one person pointed out several “holes” in these rules, I started to get very disconcerted… Really, all I’m looking for is to feel as “relatively comfortable” as someone who uses Windows or Mac and merely enables the built-in firewall. I certainly am not interested in delving into any arcane logic within the various iptables rules… I just want something simple yet secure! I’ve also read various forums that say various things in this regard, such as: 1) A firewall is not needed in Linux; 2) A firewall is only needed if the Linux box is running an ssh server; 3) A firewall is not needed as long as one does not use public wifi; 4) Trisquel evidently included an ssh server by default in version 6, but not in version 7. Please help! Any advice would really be welcome here. I would define myself as someone who has done some shell scripting in the past (mainly in Unix) although currently, I want my Linux setup to be as simple and straightforward as possible, while offering a high level of security. Thanks in advance. -Harris
