-
Senior Member
registered user
I DID IT!! FINALLY!! after years of trying... well it felt like years... now, to get the firewall working!!
-
Senior Member
registered user
How did you do it ? (grin)
>>
now, to get the firewall working!!
>>
iptables will be a seperate package to your kernel. Geting the lates for your kernel flavour probably wouldn't go astray ...
www.iptables.org
aka
www.netfilter.org
And installing an Intrusion Detector can be fun too ...
www.snort.org
Not a lot seems to happen on the ping level this year though, just the usual few MySQL sniffs from china every so often ... you should have seen all the stuff going down last year though ! ... It was a total cracker free for all (grin) ... it's a bit like candid-camera in a way ... yes, we are being scaned (grin)
jm
-
Senior Member
registered user
thank-you for the links... i'm just downloading them... but i still might need some more help...
-
Senior Member
registered user
Not a problem
, its' been a while since i looked into them, so i'll probably have to go over that a bit.
Aside from the compile/install or package install ... the table configuration is the thing that most people find tricky.
There are a number of front-ends around to automate that "Guard Dog" being popular. There are a few though.
Script/manual config isn't that hard though ... and differes considerably depending on your setup.
For an ordinary home-user like myself, just on dialup, it wasn't that involved.
Basicaly it is just a list of rules ... which involve a pattern to match to, and a target to jump to when matched.
The pattern can be a specific port, a specific address, a range of those ... or it can involve state. Such as whether the packet has its' "SYN" bit set or not, or if it's an AKN (acknoledgement) packet.
Your targets are basically "Accept", "LOG" or "DROP", and you can have user defined targets. Which are good for organising the handleing of different packet protocols.
Snort is a good system too, for getting a look at what kind of activity is actually hanging around your connection.
I get the feeling you may well find it quite fun putting together. And, of course ... it does give one a certain sence of control/power over their box (grin)
An essential facility really ...

jm
-
Senior Member
registered user
i'm really c*** at compiling, no matter what i do, i fail... how do you do it... and do you have screen shots of doing it??
-
Senior Member
registered user
>>
screen shots
>>
hehehe, ... no, not really (grin)
There's a program around called 'checkinstall' that a lot of people use to create packages from raw compiles. It will do deb, slack and rpm packaging. You may find that usefull ..... but as far as compiling goes ... it's quite straight forward. It does, like most things, depend on how attentive the developer/maintainer was when they put it together though
.
You just expand a compressed sorce file package in some convieniant place, and then spend a bit of time going over the documentation. After doing that it usually just a matter of doing ...
]$ ./configure
]$ make
]# make install
The last usually requires root permissions.
Redirecting those to log files is recomended too. So as to provide a means of tracing back over the processes, such as ...
./configure 2>&1 |tee zconfig-out.log
Making a backup of the generated Makefile is a good idea as well, you could also add CFLAG switches to further optimise the compile for your particular processor.
The only real cavet would be in keeping track of what gets put where ... so, some way of packaging it for the distro type tends to be handy .. thus, "checkinstall"
Iv'e been known to install an out of date deb package, then compile the latest source with the configue switches that govern where things go, set to reflect that. Then just installed on top of it. Messy (grin), and not that professional, but what the heck ... it worked at the time.
]$ ./configure --help will give you all the information needed for the source concerned. The output there may vary in some respects depending on the source.
The only thing that might crop up would involve development packages that may not be on the system, but are required for the installation. Basically just header files and statick libraries used for the build.
debs main site can give a good run down on what a particular source may require.
With debian ... you could try down loading the three files that make up a particular source set. Preferably from stable or testing rather than sid. That just involves ...
package.orig.tar.gz
package.diff.gz
pacage.dsc
You put those in a directory and do ...
]$ dpkg-source -x package.dsc
]$ cd <package_directory>
]$ dpkg-buildpackage -rfackroot
If your lucky that should generate a nice new set of deb packages ready to install on any debian based system. But (grin), one must always remember ... deb will be deb 
Again the main problem will involve library dependencies. deb tends to keep them tight (grin)
But where there's a will there's a way. Things like ... it wants tdk4.0 abd your've got v3.8 ... hmmmmm, just edit the ",dsc" file, and possibly the "control" file in the debian subdirectory of the package directory.
Oh yes, have a look in the Makefile for a variable called "DESTDIR=". It isn't always there, but often is. If it is found, and it's not a deb build, if you give it a directory path, the install will be made under the directory that it points to.
It can be handy to use for an initial test install, just to get a handle on just how many files there are and where theregoing to be placed. Then just set it back to null and run it again.
It usually works out smoothly though, and can be a lot of fun ...
Just jump straight in
.
jm
-
Senior Member
registered user
guess what... i did it... HORAY!! finally, something successful...
and i apt-get updated sucessfully
and downloaded k3b successfully
and also passed at shields up... got %100...
perfect...
and the firewall is working perfectly... yay!!
-
Senior Member
registered user
-
Senior Member
registered user
If you install via a deb pakage, the installation should also setup it's start up configuration. I disable its' starting within a runlevel, as i figure it's no needed as a daemon when i'm not on-line.
So i start it via a script run as part of ppp starting up ...
/etc/ppp/ip-up.d/snort.
Its main configuration will involve a set of files found in
/etc/snort/
snort.conf, snort.debian.conf and snort.rules.include being the main ones to look at.
It will probably take a bit of tweaking as there a various leves that snort can operate on. It can do full packet sniffing, or youcan restrict it to just sniff the headers etc.
It's a nice utility, and quite interesting to investigate. And it will involve some documentation reading (grin).
I would even say it should be thought of as an essential package.
So ... you got iptables working. What did you actually do there for the configuration issues ?
jm
-
Senior Member
registered user
>>you got iptables working. What did you actually do there for the configuration issues ?<< way to tired to know what this means... really tired...
anyway... spotted something on BSG, the girl says "We should get a copy of your brain patterns"... if they made him, they would already have a copy of his brain patterns... SO...
is he a cylon??? *dramatic music*
Similar Threads
-
By BubbaCola in forum Hdd Install / Debian / Apt
Replies: 4
Last Post: 10-15-2004, 09:40 AM
-
By unamiccia in forum Hdd Install / Debian / Apt
Replies: 3
Last Post: 03-16-2004, 06:38 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

OWC Mercury Elite Pro 2 Bay RAID Enclosure with USB 3.2 for Dual 3.5 inch HDDs
$87.99

Broadcom MegaRAID 9480-8e Fujitsu PRAID EP540e SAS RAID Card (Replac 9380-8e) 8i
$228.00

Areca ARC-1882IX-24 (16i4e)24-Port RAID Controller Card w/BBU /HDD Monitor Board
$300.00

Broadcom 9600-24i RAID Controller PCIe Gen 4.1 Tri-Mode NEW 05-50111-01004
$649.99

Broadcom LSI 9305-16i 12Gbps SAS-3 PCIe x8 HBA 16-Ports Raid Controller
$64.99

Promise Pegasus3 Series R4 12TB 4-bay Thunderbolt 3 RAID Storage
$500.00

Dell PowerEdge HBA330 LP PCI-E 12GBs RAID SAS Controller Adapter J7TNV
$18.95

LSI 9305-16i SATA SAS 12Gbs Controller card PCIe 3.0 IT-Mode w/SAS SATA cable US
$125.98

G-Technology G-SPEED Studio XL 48TB Thunderbolt 2 Storage - Housing Only
$200.00

CalDigit VR minin 2 Portable Raid Storage On The Go
$75.00