We’ve all run into UFW on Linux systems that were already in use. When firewall problems show up, they almost never show up in new or surprising ways. We at Linux Security want to help other admins recognize the kind of UFW problem they’re dea...
This article is a good discussion about what a firewall can be expected to do, and what it can't. "In most organizations, firewalls are now a commodity: everyone has at least one. In the future, access controls will need to become . . .
This is another document on using TCP Wrappers and building a quick firewall script. "The simplest way to secure your machine (short of locking it up in the wine cellar with no Internet connection) is to disable all nonessential services from . . .
Corrections to path issues relating to use of script with Red Hat Linux and from ip-up scripts, a test for ipchains kernel support, and a few minor bugfixes with interface detection routines. "ipchains-firewall is an easily-configurable shell script to establish masquerading . . .
There are many common configuration problems with firewalls, ranging in severity and scope. By far the most common problems relate to what should be blocked or allowed. This is often problematic because needs change; you may need to allow video-streaming, for . . .
Security is no good if it isn't in the right place. Think about a modern office building - where are the doors with locks? The lobby doors can always be locked, and usually the doors on each floor have locks as . . .
You've seen those cute little Cobalt cube servers on television, in magazines, and in your dreams, but you haven't taken the time to give one a test run. Why? Who really knows what they're for? Web servers? File servers? Print servers? . . .
Firewalls seem to be the stuff of legend in the IT community. Everyone has one because they're afraid of system crackers, viruses, and other nefarious things, but very few people know what a firewall is, let alone how to construct one. . . .
While Checkpoint issues service pack to address vulnerabilities, hackers warn against placing too much faith in firewalls. An audience of several hundred network security professionals watched with rapt attention last week as a trio of hackers repeatedly penetrated one of the . . .
Firestarter is a complete firewalling tool for Linux. Features include a firewall wizard, on the fly firewall shaping, a real time hit monitor and IP Masquerade support. Firestarter is made for the GNOME desktop.
Here's a quick 12 tips that describes a firewall, and how to build one. 1.A firewall implements your security policy. A firewall enforces some security policy. If you didn't have a security policy before you put the firewall in place, you . . .
If you haven't heard of TCP Wrappers, or are interested in making it work a bit better, this is a good article to read. "TCP wrappers are designed to filter incoming connections to network services. In this article Paul Dunne . . .
The firewall, which has served as the sentry between the outside world of the Internet and the internal agency network, may be moving inside the network perimeter to World Wide Web servers, PCs, modems and silicon chips. Such internal firewalls . . .
... "Such internal firewalls -- known as distributed firewalls -- are the next line of defense against hackers who breach traditional firewalls by exploiting open ports and e-mail servers. Network managers tend to see distributed firewalls as added firepower against . . .
Here is an interesting FAQ that you may want to consider reading. "This FAQ describes basic Linux Ethernet connection and home LAN configuration. Particular emphasis is placed on network security and firewall construction. The examples are based on Red Hat Linux . . .
This LG article discusses configuring an old 486 machine as a secure Internet gateway with two ethernet interfaces. "When finished this will be a very lean install, weighing in at about 130 MB plus swap, there will be no X . . .
This is an introductory document describing firewalls and performing an installation of TheEdge FirePlug. "Edge FirePlug is a very well-designed firewall solution from FirePlug Computers, Inc. in Vancouver, BC. One of the reasons I chose Edge FirePlug (just called . . .
This article documents how to setup a firewall using a PPP dialup with FreeBSD and IPFW, and specifically with firewalling over a dialup with a dynamically assigned IP address. It does not cover how to setup a standard PPP . . .
In mid-May, Linux.com released Part 1 - 'An Introduction to IP Masquerading.' Here is 2nd and final part of this article. "Now that relatively high-bandwidth Internet connections are becoming both commonplace and inexpensive, cable modem and DSL users wanting . . .
We are linking our company to the Internet, and we are discussing the placement of the firewall. I feel that the firewall should reside in-house for the best security; others want to put the firewall at our ISP and run . . .