-
Senior Member
registered user
--With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.
--Putting /home itself on a separate partition is a good idea though, as it can last through various flavors of Linux as well as being a bit more secure.
--Which flavor do you run on your Linux router? Have you used LRP*, and do you recommend it?
--The part that I'm most interested in, having never done a software router myself (tried the Linksys hardware DSL sharing solution, but since it only uses class C (192.168...) it didn't work with my Class A setup {10.0...}) is the actual rules that people use in RL. Rickenbacherus, if you or anyone else could post an example of what specific rules you use and why, it would be a great help to me.
( * LRP:
http://freshmeat.net/projects/linuxr.../?topic_id=864,
http://www.linuxrouter.org/ )

Originally Posted by
rickenbacherus
Your concerns John Doe are why I choose to run a Linux router....(snip)
If you want
real security build your own router. Boot the OS from a removable disc, either a floppy or cdrom. If your router OS is installed on a hard drive then it can be written to-
period.
(snip)
Build a router, make it small, make it cool looking- install Linux to your network machines, put each users /home directory on a seperate partition, don't get lazy with permissions and you will likely never reinstall an OS again.
Well ok that's not entirely true. You see...............Linux in and of itself is highy addictive and you will soon find yourself saying "so many distro's so little time".

-
Senior Member
registered user

Originally Posted by
Dave_Bechtel
--With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.
True....I have never had that many either but certainly it would be possible to run out.
Here is _Shields Up which just scans some commmon ports- note the hilarious dialouge about windows network machines....
----------------------------------------------------------------------------------------------------------
Shields UP! is checking YOUR computer's Internet
connection security . . . currently located at IP:
xx.xx.xx.xx
Please Stand By. . .
Attempting connection to your computer. . .
Shields UP! is now attempting to contact the Hidden Internet Server within your PC. It is likely that no one has told you that your own personal computer may now be functioning as an Internet Server with neither your knowledge nor your permission. And that it may be serving up all or many of your personal files for reading, writing, modification and even deletion by anyone, anywhere, on the Internet!
Preliminary Internet connection refused!
This is extremely favorable for your system's overall Windows File and Printer Sharing security. Most Windows systems, with the Network Neighborhood installed, hold the NetBIOS port 139 wide open to solicit connections from all passing traffic. Either this system has closed this usually-open port, or some equipment or software such as a "firewall" is preventing external connection and has firmly closed the dangerous port 139 to all passersby. (Congratulations!)
Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
----------------------------------------------------------------------------------------------------------
Now- just for the fun of it let's add these rules to the ipchains:
/sbin/ipmasqadm autofw -A -r tcp 1 65535 -h 192.168.0.99
/sbin/ipmasqadm autofw -A -r udp 1 65535 -h 192.168.0.99
These rules will stealth all ports by forwarding them to a non-existant machine on my network.
Ok let's do the port scan at shieldsup again:
---------------------------------------------------------------------------------------------------------
Your Internet port 139 does not appear to exist!
One or more ports on this system are operating in FULL STEALTH MODE! Standard Internet behavior requires port connection attempts to be answered with a success or refusal response. Therefore, only an attempt to connect to a nonexistent computer results in no response of either kind. But YOUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which represents advanced computer and port stealthing capabilities. A machine configured in this fashion is well hardened to Internet NetBIOS attack and intrusion.
Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
----------------------------------------------------------------------------------------------------------
Here's Sygate's results:
FTP DATA
20
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FTP
21
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SSH
22
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
TELNET
23
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SMTP
25
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DNS
53
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
DCC
59
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
FINGER
79
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
WEB
80
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
POP3
110
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
IDENT
113
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
NetBIOS
139
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
HTTPS
443
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
Server Message Block
445
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOCKS PROXY
1080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
WEB PROXY
8080
BLOCKED
This port has not responded to any of our probes. It appears to be completely stealthed.
SOURCE PORT
61897
BLOCKED
This is the port you are using to communicate to our Web Server. A firewall that uses Stateful Packet Inspection will show a 'BLOCKED' result for this port.
I think that this should quash any doubts about how secure a Linux router can be. I'd love to see some dlink and netgear results.
I use Coyote Linux which borrows heavily from LRP. In fact some of the LRP add-on packages have been converted for use in Coyote. I can access my router via web browser, make backup copies of my router floppy, ssh, restart firewall rules with a simple command of firewall-r and a host of other features.
Of course I'll need to unstealth a port for ssh to work again.
Similar Threads
-
By prelude in forum Networking
Replies: 7
Last Post: 09-15-2004, 04:17 AM
-
By lordb in forum Hdd Install / Debian / Apt
Replies: 1
Last Post: 05-02-2004, 06:43 AM
-
By alxdotnet in forum Hdd Install / Debian / Apt
Replies: 0
Last Post: 02-12-2004, 05:57 PM
-
By Bd84 in forum General Support
Replies: 12
Last Post: 05-27-2003, 04:16 PM
-
By WT in forum General Support
Replies: 1
Last Post: 12-31-2002, 09:21 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

GIGABYTE A520M DS3H AC AMD AM4 Motherboard mATX
$59.99

Intel H310 LGA1151 8-9th Gen DDR4 M.2 NVMe mATX Motherboard IO Shield Battery
$54.99

Intel H81 Motherboard M.2 NVMe LGA 1150 mATX w/ IO Shield (Random Slot Color)
$29.90

ASUS B85M-G / B85M-G PLUS LGA1150 DDR3 Micro ATX Motherboard HDMI Support 4thCPU
$45.00

GIGABYTE B365 HD3 LGA1151 Intel 9th Gen motherboard
$59.99

ASUS PRIME B360M-C MicroATX Intel LGA1151 DDR4 HDMI VGA USB RJ-45 Audio
$34.99

ASRock B550M PRO4 AM4 AMD B550 SATA 6Gb/s Micro ATX AMD Motherboard
$76.49

ASUS PRIME Z370-A II LGA 1151 Intel Z370 DDR4 DIMM USB3.1 DVI ATX RGB
$69.99

B85M-G Motherboard Intel Core i7-4770 CPU LGA1150 mATX 4 DIMM IO Shield
$75.96

ASRock Z370 Pro4 LGA 1151 Z370 HDMI USB 3.1 2 Ultra M.2 DDR4 ATX Motherboard
$75.00