View previous topic :: View next topic |
Author |
Message |
Annom n00b
Joined: 08 Dec 2003 Posts: 14 Location: Far far away...
|
Posted: Mon Dec 15, 2003 3:08 am Post subject: Best firewall to use? |
|
|
hey all, wats the best firewall to use with gentoo? or is it safe enough without one? _________________ .......... i dont think its supposed to do that .......... |
|
Back to top |
|
|
greml!n Apprentice
Joined: 29 Mar 2003 Posts: 159
|
Posted: Mon Dec 15, 2003 4:55 am Post subject: Shorewall |
|
|
Shorewall (google it, I'm lazy) is by far the best firewall package I've used. Configure makes sense without having to analyze every possible security hole and it comes with several pre-defined scenarios for common deployments. The community is also very active for support.
Two thumbs up. |
|
Back to top |
|
|
ikaro Advocate
Joined: 14 Jul 2003 Posts: 2527 Location: Denmark
|
|
Back to top |
|
|
haz3l n00b
Joined: 11 Dec 2003 Posts: 39 Location: San Francisco
|
Posted: Mon Dec 15, 2003 7:56 am Post subject: |
|
|
If you feel like being hardcore, build your kern with iptables support and write a set of rules. That is IMO the *best* way to do it because you know exactly what your firewall is doing..
Safe without one? Depends on what you're running. If you have no services, or most are up to date, and you have a kern without that recent bug, its "safe".. I wouldn't do it myself. |
|
Back to top |
|
|
Bash[DevNull] Guru
Joined: 10 Oct 2003 Posts: 333
|
Posted: Mon Dec 15, 2003 9:24 am Post subject: |
|
|
haz3l wrote: | If you feel like being hardcore, build your kern with iptables support and write a set of rules. That is IMO the *best* way to do it because you know exactly what your firewall is doing..
Safe without one? Depends on what you're running. If you have no services, or most are up to date, and you have a kern without that recent bug, its "safe".. I wouldn't do it myself. |
Hey Man, Shoreline Firewall is only wrapper for iptables for more user friendly configurations and making security policing... _________________ Biomechanical Artificial Sabotage Humanoid |
|
Back to top |
|
|
GurliGebis Retired Dev
Joined: 08 Aug 2002 Posts: 509
|
Posted: Mon Dec 15, 2003 9:47 am Post subject: |
|
|
I would surgest making it yourself with iptables, you learn more by doing that _________________ Queen Rocks. |
|
Back to top |
|
|
Bash[DevNull] Guru
Joined: 10 Oct 2003 Posts: 333
|
Posted: Mon Dec 15, 2003 10:06 am Post subject: |
|
|
GurliGebis wrote: | I would surgest making it yourself with iptables, you learn more by doing that |
I agree with you, but only at first time to good understanding what happend exactly inside you linux. But when yuor Net is very big, and so many station in.... to help you coming tools. But... i am only generate rules for firewall at start and when manuall edited them for more flexibility _________________ Biomechanical Artificial Sabotage Humanoid |
|
Back to top |
|
|
haz3l n00b
Joined: 11 Dec 2003 Posts: 39 Location: San Francisco
|
Posted: Mon Dec 15, 2003 2:31 pm Post subject: |
|
|
Hrm. Maybe I'll try shoreline ^^ |
|
Back to top |
|
|
cram Guru
Joined: 17 Nov 2002 Posts: 312 Location: Saskatoon, Canada
|
Posted: Mon Dec 15, 2003 4:25 pm Post subject: |
|
|
Just like to point out that the correct address for shoreline firewall is www.shorewall.net. The address given by ikaro a few posts above seems to be for a texas christian center. _________________ aaarggghhhh.
Good point Chewie. |
|
Back to top |
|
|
Slurp53 Apprentice
Joined: 14 Jun 2002 Posts: 255 Location: Iowa
|
Posted: Mon Dec 15, 2003 5:55 pm Post subject: |
|
|
I use firestarter mostly because it logs the hits your firewall is taking. You can find it here http://firestarter.sourceforge.net/ Works great and is very easy to use.
_________________ "Welcome to the Pleasuredome" -- Frankie Goes to Hollywood |
|
Back to top |
|
|
nbensa l33t
Joined: 10 Jul 2002 Posts: 799 Location: Buenos Aires, Argentina
|
Posted: Mon Dec 15, 2003 5:59 pm Post subject: |
|
|
For starters: shorewall. But it doesn't hurt to learn iptables too |
|
Back to top |
|
|
Annom n00b
Joined: 08 Dec 2003 Posts: 14 Location: Far far away...
|
Posted: Mon Dec 15, 2003 6:49 pm Post subject: |
|
|
as im a fussy bugger, ill give all the firewalls and other suggestions a try to find out wat i find the easiest and the best, thanks for the info _________________ .......... i dont think its supposed to do that .......... |
|
Back to top |
|
|
|