-
Senior Member
registered user
--With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.
--Putting /home itself on a separate partition is a good idea though, as it can last through various flavors of Linux as well as being a bit more secure.
--Which flavor do you run on your Linux router? Have you used LRP*, and do you recommend it?
--The part that I'm most interested in, having never done a software router myself (tried the Linksys hardware DSL sharing solution, but since it only uses class C (192.168...) it didn't work with my Class A setup {10.0...}) is the actual rules that people use in RL. Rickenbacherus, if you or anyone else could post an example of what specific rules you use and why, it would be a great help to me.
( * LRP:
http://freshmeat.net/projects/linuxr.../?topic_id=864,
http://www.linuxrouter.org/ )

Originally Posted by
rickenbacherus
Your concerns John Doe are why I choose to run a Linux router....(snip)
If you want
real security build your own router. Boot the OS from a removable disc, either a floppy or cdrom. If your router OS is installed on a hard drive then it can be written to-
period.
(snip)
Build a router, make it small, make it cool looking- install Linux to your network machines, put each users /home directory on a seperate partition, don't get lazy with permissions and you will likely never reinstall an OS again.
Well ok that's not entirely true. You see...............Linux in and of itself is highy addictive and you will soon find yourself saying "so many distro's so little time".

-
Senior Member
registered user

Originally Posted by
Dave_Bechtel
--With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.
True....I have never had that many either but certainly it would be possible to run out.
Here is _Shields Up which just scans some commmon ports- note the hilarious dialouge about windows network machines....
----------------------------------------------------------------------------------------------------------
Shields UP! is checking YOUR computer's Internet
connection security . . . currently located at IP:
xx.xx.xx.xx
Please Stand By. . .
Attempting connection to your computer. . .
Shields UP! is now attempting to contact the Hidden Internet Server within your PC. It is likely that no one has told you that your own personal computer may now be functioning as an Internet Server with neither your knowledge nor your permission. And that it may be serving up all or many of your personal files for reading, writing, modification and even deletion by anyone, anywhere, on the Internet!
Preliminary Internet connection refused!
This is extremely favorable for your system's overall Windows File and Printer Sharing security. Most Windows systems, with the Network Neighborhood installed, hold the NetBIOS port 139 wide open to solicit connections from all passing traffic. Either this system has closed this usually-open port, or some equipment or software such as a "firewall" is preventing external connection and has firmly closed the dangerous port 139 to all passersby. (Congratulations!)
Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
----------------------------------------------------------------------------------------------------------
Now- just for the fun of it let's add these rules to the ipchains:
/sbin/ipmasqadm autofw -A -r tcp 1 65535 -h 192.168.0.99
/sbin/ipmasqadm autofw -A -r udp 1 65535 -h 192.168.0.99
These rules will stealth all ports by forwarding them to a non-existant machine on my network.
Ok let's do the port scan at shieldsup again:
---------------------------------------------------------------------------------------------------------
Your Internet port 139 does not appear to exist!
One or more ports on this system are operating in FULL STEALTH MODE! Standard Internet behavior requires port connection attempts to be answered with a success or refusal response. Therefore, only an attempt to connect to a nonexistent computer results in no response of either kind. But YOUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which represents advanced computer and port stealthing capabilities. A machine configured in this fashion is well hardened to Internet NetBIOS attack and intrusion.
Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
----------------------------------------------------------------------------------------------------------
Here's Sygate's results:
FTP DATA
20
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FTP
21
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SSH
22
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
TELNET
23
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SMTP
25
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DNS
53
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DCC
59
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FINGER
79
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
WEB
80
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
POP3
110
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
IDENT
113
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
NetBIOS
139
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
HTTPS
443
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
Server Message Block
445
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOCKS PROXY
1080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
WEB PROXY
8080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOURCE PORT
61897
BLOCKED
This is the port you are using to communicate to our Web Server. A firewall that uses Stateful Packet Inspection will show a 'BLOCKED' result for this port.
I think that this should quash any doubts about how secure a Linux router can be. I'd love to see some dlink and netgear results.
I use Coyote Linux which borrows heavily from LRP. In fact some of the LRP add-on packages have been converted for use in Coyote. I can access my router via web browser, make backup copies of my router floppy, ssh, restart firewall rules with a simple command of firewall-r and a host of other features.
Of course I'll need to unstealth a port for ssh to work again.
Similar Threads
-
By prelude in forum Networking
Replies: 7
Last Post: 09-15-2004, 04:17 AM
-
By lordb in forum Hdd Install / Debian / Apt
Replies: 1
Last Post: 05-02-2004, 06:43 AM
-
By alxdotnet in forum Hdd Install / Debian / Apt
Replies: 0
Last Post: 02-12-2004, 05:57 PM
-
By Bd84 in forum General Support
Replies: 12
Last Post: 05-27-2003, 04:16 PM
-
By WT in forum General Support
Replies: 1
Last Post: 12-31-2002, 09:21 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

INTEL XEON E5-2680V4 SR2N7 2.40GHZ CPU
$11.00

Dell Precision Tower 7810 Xeon E5-2630 v3 @ 2.40GHz , 32GB Ram, NO HDD, NO OS
$239.99

Dell Precision T7820 2x Xeon Silver 4114 2.20GHz 950W No RAM GPU HDD 4x SATA
$350.48

Dell Precision T5820 950W Workstation 4.00GHz W-2125 No RAM/ GPU/ HDD/ OS
$144.98

Dell Precision T5820 Workstation 3.70GHz W-2135 No RAM/ GPU/ HDD/ OS
$179.98

Intel Xeon E5-2699 V4 2.20GHz 55M 22-CORES LGA2011-3 Server Processor 145W SR2JS
$84.49

DELL Precision 5820 Workstation Xeon W-2123 3.6ghz/NO RAM/NO SSD/P400 Vid
$139.99

Dell Precision T5820 Workstation 3.70GHz W-2135 32GB No GPU/ HDD/ OS DISCOUNTED
$363.94

Dell PowerEdge FX2s + 8x FC430 Blades 16x E5-2630v4 160 Cores Rails No PSU/RAM
$699.00

Dell EMC PowerEdge R440 Xeon silver 4215 2.5GHz 16 GB ram 2x 550W PSU No HDD
$275.00