Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Gentoo firewall from the security docs
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
UberLord
Retired Dev
Retired Dev


Joined: 18 Sep 2003
Posts: 6835
Location: Blighty

PostPosted: Thu Oct 09, 2003 1:30 pm    Post subject: Gentoo firewall from the security docs Reply with quote

I've decided to use the firewall script supplied in the Gentoo security docs as it seems to do the job. I've made a few alterations to it for ease of use - basically this is for my laptop for use at work and home.

I've allowed by default anything to go out so I don't have to mess around with anything too much. This allows my various net proggies to work.

As I'm not allowing anything in except ssh from specific IP's this should be safe - yes? Also, the laptop is behind a decent firewall at work and a crappy firewall on my ADSL router at home, so it shouldn't be too bad.

Comments?
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Thu Oct 09, 2003 2:28 pm    Post subject: Reply with quote

So why a firewall at all? :twisted:

Honestly, at work it is the job of the firewall admins to secure the network so you should not need one on your laptop.
At home (if your ADSL router does NAT) it is not needed too, it's enough to configure you SSH correctly.
The only thing you need is to restrict the IP which are allowed to connect to your SSH - if your router can't do this (most probably not).

On the other hand... only the paranoid survive

T.
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
ronmon
Veteran
Veteran


Joined: 15 Apr 2002
Posts: 1043
Location: Key West, FL

PostPosted: Thu Oct 09, 2003 2:51 pm    Post subject: Reply with quote

The firewall at work might help prevent attack from external sources, but probably not from other users of the company intranet. As long as your firewall rules don't prevent you from accessing what you need, it's a good idea and certainly can't hurt.

NAT is not a security measure, but through obfuscation it makes it a bit more complicated for a potential cracker to find you. Again, the local firewall is your last line of defense and can only help.

Through the millennia it has been proven that whether protecting a city, an airbase, an embassy or a computer, a layered defense is the most effective plan.
Back to top
View user's profile Send private message
UberLord
Retired Dev
Retired Dev


Joined: 18 Sep 2003
Posts: 6835
Location: Blighty

PostPosted: Thu Oct 09, 2003 3:03 pm    Post subject: Reply with quote

Think4UrS11 wrote:
So why a firewall at all? :twisted:


Healthy paranoia :lol:

Don't trust a few computers @ work and as the other guy said the local fw is the last line of defence.

Say the laptop had a direct feed to the internet, only ssh would be accessable externally? Excellent :)
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Thu Oct 09, 2003 3:21 pm    Post subject: Reply with quote

we are on line - parnoia is why i'm still alive :twisted:

of course you are right with layered security, but...
it makes no real difference (asides the restricions for some IP) between having only SSH or iptables+SSH with a ssh-rule for iptables
The packets will come to sshd in both cases, right?
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
UberLord
Retired Dev
Retired Dev


Joined: 18 Sep 2003
Posts: 6835
Location: Blighty

PostPosted: Thu Oct 09, 2003 3:25 pm    Post subject: Reply with quote

On another note, would the same configuration be relatively safe for a Server with a direct internet feed also doing NAT for local clients?

My home network runs a whole load of games over various ports and stuff.

I like the smoothwall config actually. I administer the one at work :twisted:

How would I go about allowing only ports > 1024 through by default and then specifying others? Like http/https etc etc.

Thanks :)
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Thu Oct 09, 2003 3:38 pm    Post subject: Reply with quote

you would always have the risk that your server is open to the internet

this may be due to misconfiguration, lazyness, various errors, server overload, ...
in general it is a 100%-NONO to combine server+firewall on one machine!

Its a matter of costs of course so many do it that (cheaper/more unsecure) way. And to be honest... the setup over here will be the same as soon as the hardware for the new 'firewall_nat_router-vpn_gateway-wlan_ap-file/print_server'-box is here.
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum