Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Firewall question so basic it's sad [SOLVED]
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Steve S.
Tux's lil' helper
Tux's lil' helper


Joined: 22 Sep 2005
Posts: 131

PostPosted: Tue Nov 22, 2005 2:06 pm    Post subject: Firewall question so basic it's sad [SOLVED] Reply with quote

Hello all,

I'm loath to ask something so seemingly simple, but I couldn't find it in the handbook, searching the forums, etc. Most assuredly, I'm looking in the wrong place, but would some one please help this simple noob out by answering his piddly question:

How do I set up a firewall with Gentoo?

I have looked through gnome, trying to find something under applications and the like that I missed, but I don't see anything obvious.

I want to set up SSH but don't want to if I can't have a simple firewall first.

Thanks for any info that you can give me.


Last edited by Steve S. on Tue Nov 22, 2005 7:58 pm; edited 1 time in total
Back to top
View user's profile Send private message
BlakeJob
Tux's lil' helper
Tux's lil' helper


Joined: 23 May 2004
Posts: 80

PostPosted: Tue Nov 22, 2005 2:11 pm    Post subject: Reply with quote

I've used shorewall as a software firewall in the past.
Back to top
View user's profile Send private message
ecosta
Guru
Guru


Joined: 09 May 2003
Posts: 477
Location: Brussels,BE

PostPosted: Tue Nov 22, 2005 2:17 pm    Post subject: Reply with quote

Hi Steve,
No stupid questions here!

You have many apps to help you configure your firewall. To findout which they are, the simplest would be to have a look at what is in "/usr/portage/net-firewall". I use shorewall. So if you want some basic info about it do:

Code:
# emerge --search shorewall


You will have to configure your kernel to suport netfilter

Code:
# cd /usr/src/linux
# make menuconfig


Symbol: NETFILTER [=y]
Prompt: Network packet filtering (replaces ipchains)
Defined at net/Kconfig:62
Depends on: NET
Location:
-> Networking
-> Networking support (NET [=y])
-> Networking options

As for enabling ssh. I don't think it's a great risk. You would be far more secure to close any open ports than worry about a firewall. run netstat
Code:
netstat -vat

and check what ports are open and close all unneeded ones. ssh is pretty safe!

Hope this helps
_________________
Linux user #201331
A8N-SLI Delux / AMD64 X2 3800+ / 1024 MB RAM / 5 x 250 GB SATA RAID 1/5 / ATI Radeon X700 256MB.
Back to top
View user's profile Send private message
rev138
l33t
l33t


Joined: 19 Jun 2003
Posts: 848
Location: Vermont, USA

PostPosted: Tue Nov 22, 2005 2:23 pm    Post subject: Reply with quote

If you're feeling n00bish, shorewall (and many other things) can be configured quite easily through Webmin, which is also in portage.
Back to top
View user's profile Send private message
at240
l33t
l33t


Joined: 12 Aug 2005
Posts: 603
Location: UK

PostPosted: Tue Nov 22, 2005 2:23 pm    Post subject: Reply with quote

Don't forget the Gentoo Wiki too---there's at least one 'iptables for noobs' article. Alternatively, if you want something really simple and user-friendly, check out firestarter.
Back to top
View user's profile Send private message
Steve S.
Tux's lil' helper
Tux's lil' helper


Joined: 22 Sep 2005
Posts: 131

PostPosted: Tue Nov 22, 2005 2:42 pm    Post subject: Reply with quote

Wow! Unfortunately this may start a trend: since it is so easy to get great responses, I may simply have to ask more questions. :wink:

That being said, I checked in my /usr/portage/net-firewall and discovered that I have firestarter, shorewall and a variety of others.

The question now is, as told to a noob that is used to the gui world (myself), how does one go about setting one of these firewalls up?
Back to top
View user's profile Send private message
magor
n00b
n00b


Joined: 15 Sep 2005
Posts: 12

PostPosted: Tue Nov 22, 2005 2:50 pm    Post subject: Reply with quote

Check your kernel config and if necessary make menuconfig as described above than just emerge firestarter/shorewall/whatever.
Back to top
View user's profile Send private message
at240
l33t
l33t


Joined: 12 Aug 2005
Posts: 603
Location: UK

PostPosted: Tue Nov 22, 2005 2:54 pm    Post subject: Reply with quote

Steve, if you're interested in firestarter, have a look at its documentation on its website: http://www.fs-security.com/

The documentation is very, very simple and clearly written. It might not be the most powerful or sophisticated firewall (I'm saying that because I really don't know about some of the alternatives), but it has a really easy graphical interface.
Back to top
View user's profile Send private message
rev138
l33t
l33t


Joined: 19 Jun 2003
Posts: 848
Location: Vermont, USA

PostPosted: Tue Nov 22, 2005 3:02 pm    Post subject: Reply with quote

I'll repeat my recommendation for webmin. It think it's an excellent system administration tool for a newbie, since it lets you configure dozens of common programs through an easy web interface.

Code:
# emerge -av webmin
Back to top
View user's profile Send private message
Steve S.
Tux's lil' helper
Tux's lil' helper


Joined: 22 Sep 2005
Posts: 131

PostPosted: Tue Nov 22, 2005 4:24 pm    Post subject: Reply with quote

rev138 wrote:
I'll repeat my recommendation for webmin. It think it's an excellent system administration tool for a newbie, since it lets you configure dozens of common programs through an easy web interface.

Code:
# emerge -av webmin


All right, rev138, I gave webmin a shot. I emerged it as indicated, then even added the rc-update line to get it to start at startup.

The question is now, how do I run it? Does it have a gui interface/icon that appears in gnome? If so, how do I get it to appear? How do I get to it?
Back to top
View user's profile Send private message
rev138
l33t
l33t


Joined: 19 Jun 2003
Posts: 848
Location: Vermont, USA

PostPosted: Tue Nov 22, 2005 4:27 pm    Post subject: Reply with quote

Steve S. wrote:
The question is now, how do I run it? Does it have a gui interface/icon that appears in gnome? If so, how do I get it to appear? How do I get to it?


You can either reboot, and let the rc-script work its magic, or:

Code:
# /etc/init.d/webmin start


Then, open a web browser and go to http://localhost:10000

(10000 is the default webmin port. You can change this once you're logged in as root)
Back to top
View user's profile Send private message
Steve S.
Tux's lil' helper
Tux's lil' helper


Joined: 22 Sep 2005
Posts: 131

PostPosted: Tue Nov 22, 2005 4:45 pm    Post subject: Reply with quote

I had restarted and when i refreshed the forum page, it asked me whether or not to allow access. I this the magic you speak of? :wink:

So, it looks like it's doing it's thing.

Any other firewall advice from the crew before I mark this solved? Thanks again to everyone for the amazingly immediate response...very reassuring.
Back to top
View user's profile Send private message
ecosta
Guru
Guru


Joined: 09 May 2003
Posts: 477
Location: Brussels,BE

PostPosted: Wed Nov 23, 2005 9:22 am    Post subject: Reply with quote

I'd follow rev138 and install an easy graphical tool to configure your firewall. It won't have all the hype but I'm sure it will keep you protected. If your needs start outgrowing the GUI, then move to shorewall or pure iptables.

Best of luck.
Ed.
PS: Remember to start a rule stating that ssh has access or you'll lock yourself out of the box if rules are too restrictive ;)
_________________
Linux user #201331
A8N-SLI Delux / AMD64 X2 3800+ / 1024 MB RAM / 5 x 250 GB SATA RAID 1/5 / ATI Radeon X700 256MB.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum