-
Senior Member
registered user
--With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.
--Putting /home itself on a separate partition is a good idea though, as it can last through various flavors of Linux as well as being a bit more secure.
--Which flavor do you run on your Linux router? Have you used LRP*, and do you recommend it?
--The part that I'm most interested in, having never done a software router myself (tried the Linksys hardware DSL sharing solution, but since it only uses class C (192.168...) it didn't work with my Class A setup {10.0...}) is the actual rules that people use in RL. Rickenbacherus, if you or anyone else could post an example of what specific rules you use and why, it would be a great help to me.
( * LRP:
http://freshmeat.net/projects/linuxr.../?topic_id=864,
http://www.linuxrouter.org/ )

Originally Posted by
rickenbacherus
Your concerns John Doe are why I choose to run a Linux router....(snip)
If you want
real security build your own router. Boot the OS from a removable disc, either a floppy or cdrom. If your router OS is installed on a hard drive then it can be written to-
period.
(snip)
Build a router, make it small, make it cool looking- install Linux to your network machines, put each users /home directory on a seperate partition, don't get lazy with permissions and you will likely never reinstall an OS again.
Well ok that's not entirely true. You see...............Linux in and of itself is highy addictive and you will soon find yourself saying "so many distro's so little time".

-
Senior Member
registered user

Originally Posted by
Dave_Bechtel
--With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.
True....I have never had that many either but certainly it would be possible to run out.
Here is _Shields Up which just scans some commmon ports- note the hilarious dialouge about windows network machines....
----------------------------------------------------------------------------------------------------------
Shields UP! is checking YOUR computer's Internet
connection security . . . currently located at IP:
xx.xx.xx.xx
Please Stand By. . .
Attempting connection to your computer. . .
Shields UP! is now attempting to contact the Hidden Internet Server within your PC. It is likely that no one has told you that your own personal computer may now be functioning as an Internet Server with neither your knowledge nor your permission. And that it may be serving up all or many of your personal files for reading, writing, modification and even deletion by anyone, anywhere, on the Internet!
Preliminary Internet connection refused!
This is extremely favorable for your system's overall Windows File and Printer Sharing security. Most Windows systems, with the Network Neighborhood installed, hold the NetBIOS port 139 wide open to solicit connections from all passing traffic. Either this system has closed this usually-open port, or some equipment or software such as a "firewall" is preventing external connection and has firmly closed the dangerous port 139 to all passersby. (Congratulations!)
Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
----------------------------------------------------------------------------------------------------------
Now- just for the fun of it let's add these rules to the ipchains:
/sbin/ipmasqadm autofw -A -r tcp 1 65535 -h 192.168.0.99
/sbin/ipmasqadm autofw -A -r udp 1 65535 -h 192.168.0.99
These rules will stealth all ports by forwarding them to a non-existant machine on my network.
Ok let's do the port scan at shieldsup again:
---------------------------------------------------------------------------------------------------------
Your Internet port 139 does not appear to exist!
One or more ports on this system are operating in FULL STEALTH MODE! Standard Internet behavior requires port connection attempts to be answered with a success or refusal response. Therefore, only an attempt to connect to a nonexistent computer results in no response of either kind. But YOUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which represents advanced computer and port stealthing capabilities. A machine configured in this fashion is well hardened to Internet NetBIOS attack and intrusion.
Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
----------------------------------------------------------------------------------------------------------
Here's Sygate's results:
FTP DATA
20
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FTP
21
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SSH
22
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
TELNET
23
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SMTP
25
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DNS
53
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DCC
59
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FINGER
79
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
WEB
80
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
POP3
110
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
IDENT
113
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
NetBIOS
139
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
HTTPS
443
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
Server Message Block
445
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOCKS PROXY
1080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
WEB PROXY
8080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOURCE PORT
61897
BLOCKED
This is the port you are using to communicate to our Web Server. A firewall that uses Stateful Packet Inspection will show a 'BLOCKED' result for this port.
I think that this should quash any doubts about how secure a Linux router can be. I'd love to see some dlink and netgear results.
I use Coyote Linux which borrows heavily from LRP. In fact some of the LRP add-on packages have been converted for use in Coyote. I can access my router via web browser, make backup copies of my router floppy, ssh, restart firewall rules with a simple command of firewall-r and a host of other features.
Of course I'll need to unstealth a port for ssh to work again.
Similar Threads
-
By prelude in forum Networking
Replies: 7
Last Post: 09-15-2004, 04:17 AM
-
By lordb in forum Hdd Install / Debian / Apt
Replies: 1
Last Post: 05-02-2004, 06:43 AM
-
By alxdotnet in forum Hdd Install / Debian / Apt
Replies: 0
Last Post: 02-12-2004, 05:57 PM
-
By Bd84 in forum General Support
Replies: 12
Last Post: 05-27-2003, 04:16 PM
-
By WT in forum General Support
Replies: 1
Last Post: 12-31-2002, 09:21 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

Acer Predator Helios Neo 16S AI 16" i9 275HX 2S RTX 5070 Ti 32GB 1TB SSD Refurb
$1671.47

Dell Latitude 14" Laptop Computer Intel i5 Up To 32GB RAM 1TB SSD Windows 11 Pro
$316.61

Dell Latitude 14" Laptop Computer Intel i7 Up To 32GB RAM 1TB SSD Windows 11 Pro
$349.48

External SSD 1TB 2TB 4TB Portable Hard Drive USB 3.0 Type-C High Speed PC Mac
$19.99

SAMSUNG T7 Portable SSD 1TB Indigo Blue USB 3.2 Gen2 External MU-PC1T0H/AM
$159.99

Crucial MX500 1TB 2.5" SATA III Internal SSD CT1000MX500SSD1
$99.99

Acer Aspire 14" AI Copilot+PC Laptop Core Ultra 5 226V Gen 4 ARC 16GB 1TB Refurb
$462.74

Netac 2TB 1TB 500GB Internal SSD M.2 NVMe PCIe3.0 Solid State Drive lot
$129.99

Samsung 2.5" 870 EVO SSD SATA III 250GB 500GB 1TB Internet Solid State Drive Lot
$90.00

Western Digital 1TB 3.5" SATA III 7200RPM Desktop Hard Drive
$34.99