Results 1 to 9 of 9

Thread: Firewall?

  1. #1
    Junior Member registered user
    Join Date
    Mar 2005
    Posts
    12

    Firewall?

    Is there a firewall in knoppix installed by default? if so where can I take a look at it and if not where can I get one such as ZA that doesn't require manual entry of ACL lists?

    Thanks

  2. #2
    Senior Member registered user
    Join Date
    Nov 2002
    Location
    USA, IL
    Posts
    1,041

    Re: Firewall?

    --If you're installed to HD, ' apt-get install firestarter ' is what I'd recommend. There's some kind of goofy firewall involving a dog somehow on the live-cd, but IIRC it's _caused_ more problems than it has solved.

    --Myself, I use a home-brewed iptables script; but I've run into some bugs with it recently after switching to broadband.

    Quote Originally Posted by rubic_cube
    Is there a firewall in knoppix installed by default? if so where can I take a look at it and if not where can I get one such as ZA that doesn't require manual entry of ACL lists?

    Thanks

  3. #3
    Member registered user
    Join Date
    Jul 2003
    Posts
    53
    if all you want to do is browse the net safely you can use this mini-script:

    in /home/knoppix create a file called "blockall" and place the following script inside it:

    #!/bin/sh
    iptables -F
    iptables -A INPUT -p all -s 127.0.0.1 -j ACCEPT
    iptables -A INPUT -p tcp --syn -j DROP

    (==>>note: this is the edited & corrected version of the script! <<==)

    then run the following commands:

    chmod +x blockall
    sudo ./blockall

    and that's it. All your ports are closed, you cannot run any server, but you can surf safely.

    to reopen everything (to stop this script) simply execute:

    iptables -F


    HTH

  4. #4
    Senior Member registered user
    Join Date
    Nov 2002
    Location
    USA, IL
    Posts
    1,041
    --Have you tried ' nmap'ping a box running that script? There's no DROP rule...

    Quote Originally Posted by andrei
    if all you want to do is browse the net safely you can use this mini-script:

    in /home/knoppix create a file called "blockall" and place the following script inside it:

    #!/bin/sh
    iptables -F
    iptables -A INPUT -p all -s 127.0.0.1 -j ACCEPT
    iptables -A INPUT -p

    then run the following commands:

    chmod +x blockall
    sudo ./blockall

    and that's it. All your ports are closed, you cannot run any server, but you can surf safely.

    to reopen everything (to stop this script) simply execute:

    iptables -F

    HTH

  5. #5
    Junior Member registered user
    Join Date
    Mar 2005
    Posts
    12
    It's ok I'll just play around with iptables some more.

  6. #6
    Member registered user
    Join Date
    Jul 2003
    Posts
    53
    Quote Originally Posted by Dave_Bechtel
    --Have you tried ' nmap'ping a box running that script? There's no DROP rule...
    you are absolutely correct. I am sorry about being sloppy. I edited and correted the script in my post above. thanks for pointing this out to everybody

  7. #7
    Junior Member registered user
    Join Date
    Mar 2005
    Posts
    12
    Whenever I try and use the log command nothing happens.

    The general iptables -A INPUT -j LOG to log all incoming packets does not generate anything in the syslog file, what do I need to do?

  8. #8
    Member registered user
    Join Date
    Jul 2003
    Posts
    53
    Quote Originally Posted by rubic_cube
    Whenever I try and use the log command nothing happens.

    The general iptables -A INPUT -j LOG to log all incoming packets does not generate anything in the syslog file, what do I need to do?
    it is my understanding that this script does not allow for any logging. if you want to see how it works, you need to nmap it, or use an online port scanner.

  9. #9
    Junior Member registered user
    Join Date
    Mar 2005
    Posts
    12
    The code logs everything, I can read the log only by doing dmesg syslog, and I can see everything that has been logged, the weird thing is if I try to open syslog any other way it says 0 bytes, so it's empty.

Similar Threads

  1. firewall??
    By zenlakin in forum Networking
    Replies: 0
    Last Post: 03-29-2007, 02:07 PM
  2. Guarddog-Firewall
    By b4sunset in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 06-02-2005, 03:54 AM
  3. Firewall
    By swazi in forum Hdd Install / Debian / Apt
    Replies: 3
    Last Post: 10-11-2004, 04:42 PM
  4. firewall
    By dugstratton in forum Networking
    Replies: 0
    Last Post: 02-14-2004, 01:20 AM
  5. Firewall
    By georgetoon in forum General Support
    Replies: 4
    Last Post: 11-21-2003, 04:09 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Dell PowerEdge R720 Server - 2x8c CPU,256Gb RAM, 128Gb SSD/3x900Gb SAS, Proxmox picture

Dell PowerEdge R720 Server - 2x8c CPU,256Gb RAM, 128Gb SSD/3x900Gb SAS, Proxmox

$340.00



DELL PowerEdge R730XD 24x 2.5

DELL PowerEdge R730XD 24x 2.5" Server Dual 750W Dual Heatsink - BareBones TESTED

$269.99



Supermicro 4U 36 Bay Storage Server 2.4Ghz 8-C 128GB 1x1280W Rails TrueNAS ZFS picture

Supermicro 4U 36 Bay Storage Server 2.4Ghz 8-C 128GB 1x1280W Rails TrueNAS ZFS

$712.98



CSE-118 Supermicro 1U 3x GPU Server  2.6Ghz 20-C 128GB CX353A 2x1600W PSU Rails picture

CSE-118 Supermicro 1U 3x GPU Server 2.6Ghz 20-C 128GB CX353A 2x1600W PSU Rails

$454.03



Intel Xeon Gold 6140 SR3AX 2.3GHz 18-Core Processor CPU picture

Intel Xeon Gold 6140 SR3AX 2.3GHz 18-Core Processor CPU

$39.99



Intel Xeon E5-2697A V4 2.6GHz CPU Processor 16-Core Socket LGA2011 SR2K1 picture

Intel Xeon E5-2697A V4 2.6GHz CPU Processor 16-Core Socket LGA2011 SR2K1

$39.99



Intel Xeon E5-2680 v4 2.4GHz 35MB 14-Core 120W LGA2011-3 SR2N7 picture

Intel Xeon E5-2680 v4 2.4GHz 35MB 14-Core 120W LGA2011-3 SR2N7

$17.99



SR1XP Intel Xeon E5-2680 v3 12 Core 30MB 2.5GHz LGA 2011-3 A Grade Processor picture

SR1XP Intel Xeon E5-2680 v3 12 Core 30MB 2.5GHz LGA 2011-3 A Grade Processor

$5.09



HP Workstation Z640 2x Xeon E5-2623V4 32GB Ram Dual 256GB SSD K420 Linux GA picture

HP Workstation Z640 2x Xeon E5-2623V4 32GB Ram Dual 256GB SSD K420 Linux GA

$234.98



Rare WaterCooled HP Z800 Workstation Dual Xeon X5680 16GB RAM 120GB SSD Nvidia picture

Rare WaterCooled HP Z800 Workstation Dual Xeon X5680 16GB RAM 120GB SSD Nvidia

$279.56