-
Junior Member
registered user
Firewall?
Is there a firewall in knoppix installed by default? if so where can I take a look at it and if not where can I get one such as ZA that doesn't require manual entry of ACL lists?
Thanks
-
Senior Member
registered user
Re: Firewall?
--If you're installed to HD, ' apt-get install firestarter ' is what I'd recommend. There's some kind of goofy firewall involving a dog somehow on the live-cd, but IIRC it's _caused_ more problems than it has solved.
--Myself, I use a home-brewed iptables script; but I've run into some bugs with it recently after switching to broadband.
Originally Posted by
rubic_cube
Is there a firewall in knoppix installed by default? if so where can I take a look at it and if not where can I get one such as ZA that doesn't require manual entry of ACL lists?
Thanks
-
if all you want to do is browse the net safely you can use this mini-script:
in /home/knoppix create a file called "blockall" and place the following script inside it:
#!/bin/sh
iptables -F
iptables -A INPUT -p all -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -p tcp --syn -j DROP
(==>>note: this is the edited & corrected version of the script! <<==)
then run the following commands:
chmod +x blockall
sudo ./blockall
and that's it. All your ports are closed, you cannot run any server, but you can surf safely.
to reopen everything (to stop this script) simply execute:
iptables -F
HTH
-
Senior Member
registered user
--Have you tried ' nmap'ping a box running that script? There's no DROP rule...
Originally Posted by
andrei
if all you want to do is browse the net safely you can use this mini-script:
in /home/knoppix create a file called "blockall" and place the following script inside it:
#!/bin/sh
iptables -F
iptables -A INPUT -p all -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -p
then run the following commands:
chmod +x blockall
sudo ./blockall
and that's it. All your ports are closed, you cannot run any server, but you can surf safely.
to reopen everything (to stop this script) simply execute:
iptables -F
HTH
-
Junior Member
registered user
It's ok I'll just play around with iptables some more.
-
Originally Posted by
Dave_Bechtel
--Have you tried ' nmap'ping a box running that script? There's no DROP rule...
you are absolutely correct. I am sorry about being sloppy. I edited and correted the script in my post above. thanks for pointing this out to everybody
-
Junior Member
registered user
Whenever I try and use the log command nothing happens.
The general iptables -A INPUT -j LOG to log all incoming packets does not generate anything in the syslog file, what do I need to do?
-
Originally Posted by
rubic_cube
Whenever I try and use the log command nothing happens.
The general iptables -A INPUT -j LOG to log all incoming packets does not generate anything in the syslog file, what do I need to do?
it is my understanding that this script does not allow for any logging. if you want to see how it works, you need to nmap it, or use an online port scanner.
-
Junior Member
registered user
The code logs everything, I can read the log only by doing dmesg syslog, and I can see everything that has been logged, the weird thing is if I try to open syslog any other way it says 0 bytes, so it's empty.
Similar Threads
-
By zenlakin in forum Networking
Replies: 0
Last Post: 03-29-2007, 02:07 PM
-
By b4sunset in forum Hdd Install / Debian / Apt
Replies: 1
Last Post: 06-02-2005, 03:54 AM
-
By swazi in forum Hdd Install / Debian / Apt
Replies: 3
Last Post: 10-11-2004, 04:42 PM
-
By dugstratton in forum Networking
Replies: 0
Last Post: 02-14-2004, 01:20 AM
-
By georgetoon in forum General Support
Replies: 4
Last Post: 11-21-2003, 04:09 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
Cisco (SG100D-05-UK) 5-Ports External Ethernet Switch
$40.00
Cisco IE-3000-8TC Industrial Ethernet 8 Ports Managed Switch 1 Year Warranty
$114.00
Cisco Nexus 48-Port 10G SFP+ Switch N9K-9396PX w/ 9K-M12PQ 12-Port 40G QSFP
$419.99
HP ProCurve 4108gl J4865A Modular Network Switch
$119.99
New Linksys SE3005 5-port Gigabit Ethernet Switch
$18.99
Linksys SE3008 8 Ports Rack Mountable Gigabit Ethernet Switch
$21.99
NetGear ProSafe GS748T V4 48-Port Gigabit Smart Switch w/ Ears + Cord
$30.00
Netgear Prosafe GS724T V2 24-Port 10/100/1000 Gigabit Ethernet Network Switch
$27.99
Netgear ProSafe S3300-52X-POE+ 48-Port Gigabit PoE+ Stackable Network Switch
$99.99
Fortinet FortiSwitch FS-124D-POE 24 Port Gigabit Ethernet Switch UNREGISTERED
$99.97