Firewalls

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

Post Reply
User avatar
CptnObvious999
Posts: 798
Joined: Fri Jun 03, 2005 7:54 pm
Location: Maryland
Contact:

Firewalls

Post by CptnObvious999 » Wed May 03, 2006 2:45 pm

I know the chance of someone hacking into my system (by the amount I have locked it down) is not that high but I would like to setup a firewall using a GUI, what is your favorite? I have tried Guarddog which seems like it could be good if it didn't block AIM even when I allow it. Firestarter doesn't seem to allow me to add any policies even though its firewall starts. I would like something close to ZoneAlarm (the only real Windows program I miss) and it has to be free. It should be easy to use and customizable. There are quite a lot of firewalls in Portage and it would be a pain to try them all (see)

User avatar
Chess
Posts: 386
Joined: Thu Nov 17, 2005 2:06 pm
Location: Raleigh, NC
Contact:

Re: Firewalls

Post by Chess » Wed May 03, 2006 2:54 pm

CptnObvious999 wrote:Firestarter doesn't seem to allow me to add any policies even though its firewall starts.
Sure, you can add policies in Firestarter -- I have a bunch of 'em.

Here's some relevant pages from their handbook:

http://www.fs-security.com/docs/policy.php
http://www.fs-security.com/docs/policy-page.php

Firestarter is a great app. It's my favorite Linux firewall.
Chess Griffin

User avatar
CptnObvious999
Posts: 798
Joined: Fri Jun 03, 2005 7:54 pm
Location: Maryland
Contact:

Re: Firewalls

Post by CptnObvious999 » Wed May 03, 2006 3:02 pm

Chess wrote:
CptnObvious999 wrote:Firestarter doesn't seem to allow me to add any policies even though its firewall starts.
Sure, you can add policies in Firestarter -- I have a bunch of 'em.

Here's some relevant pages from their handbook:

http://www.fs-security.com/docs/policy.php
http://www.fs-security.com/docs/policy-page.php

Firestarter is a great app. It's my favorite Linux firewall.
I ment the add/remove/edit/apply policy buttons are disabled and so are the options under the policy menu.

User avatar
Chess
Posts: 386
Joined: Thu Nov 17, 2005 2:06 pm
Location: Raleigh, NC
Contact:

Post by Chess » Wed May 03, 2006 3:04 pm

Try running it as root, or using gtksu.
Chess Griffin

User avatar
CptnObvious999
Posts: 798
Joined: Fri Jun 03, 2005 7:54 pm
Location: Maryland
Contact:

Post by CptnObvious999 » Wed May 03, 2006 3:07 pm

Chess wrote:Try running it as root, or using gtksu.
I did.

EDIT: Ok nevermind it works now for some reason....

EDIT 2: The policies are not that customizable IMHO and don't have a lot of services in the menus which is kinda annoying. I guess its better than blocking AIM ;-)

User avatar
Chess
Posts: 386
Joined: Thu Nov 17, 2005 2:06 pm
Location: Raleigh, NC
Contact:

Post by Chess » Wed May 03, 2006 3:25 pm

Don't worry about the services they list -- create your own.

Right click in the area for inbound or outbound and select "add". You can then customize the rules however you want. I have ssh running on a different port than 22 and I just created a customizable rule for that. I have not found anything that it can't do.
Chess Griffin

User avatar
Chess
Posts: 386
Joined: Thu Nov 17, 2005 2:06 pm
Location: Raleigh, NC
Contact:

Post by Chess » Wed May 03, 2006 3:36 pm

BTW, another option is to use a script, which is what I have on my server. Here is a site where you can create one:

http://www.slackware.com/~alien/efg/

this is intended for Slackware, but I'm sure you can modify it for gentoo.
Chess Griffin

User avatar
CptnObvious999
Posts: 798
Joined: Fri Jun 03, 2005 7:54 pm
Location: Maryland
Contact:

Post by CptnObvious999 » Wed May 03, 2006 3:50 pm

Chess wrote:Don't worry about the services they list -- create your own.

Right click in the area for inbound or outbound and select "add". You can then customize the rules however you want. I have ssh running on a different port than 22 and I just created a customizable rule for that. I have not found anything that it can't do.
Yeah but that is slightly more annoying, also it doesn't seem to be able to block inbound traffic and output traffic can only be whitelisted or blacklisted, not a combination of the two.

User avatar
no1important
Posts: 55
Joined: Fri Aug 19, 2005 8:33 pm
Location: Vancouver BC
Contact:

Post by no1important » Wed May 03, 2006 8:44 pm

I use "guarddog" it is easy to use, easy to use interface, easy to set up, easy to change what can and can not connect to the internet. It is basically a simple straight forward firewall.

I have tried others but by far this one for me was the easiest one to set up and use. Since my conversion to linux a year and a half ago it is the only firewall I have used.

I tried to set up and use "shorewall" firewall but for the life of me I could not figure out how to use it so I went back to guarddog.

I have never tried "firestarter" though.

Post Reply