Quote Originally Posted by BoDiddley View Post
Additionally, using "netstat" I found many connections doing I/O's. and flooding me with SYN's (I think they are bad). "arno-iptables-firewall status" will also give you feedback on what the "script" is doing to protect you. After installing the firewall I saw download bursts up to 170 KBPS, never seen before. Any unwarranted connection now gets dropped. I guess I have a bad router. But routers generally ship open. I prefer to develop my security in the firewall, leaving my ISP's router as they shipped it in case I need to call them. I have tried tinkering with the router settings in the past and was almost unable to recover the original settings. (newbie x 2)
It is difficult to generalise about ISP since folks on this forum are all over the world. I guess many have a solution that uses "Internet Connection Sharing" under Windows. That may rely on firewall software running on the machine that shares out the internet connection. I'm not familiar with the technical details. When I switched to broadband my new ISP offered me the choice: use their ADSL box or my own so I bought my own. It's the DHCP server for my home LAN and came with the correct default firewall configured. It meant I've never needed to look into firewalls and proxies and all that stuff in detail.

You need a firewall between you and the Internet but it is only part of the story. There is so much misinformation out there.

SYNs are not bad. There are an essential part of establishing a TCP/IP connection. There is a particular kind of denial of service attack that floods a vulnerable system with SYNs. The vulnerable system allocates some resources and replies OK in order to complete the connection. The attacker does not complete the connection but keeps sending more SYNs. This can tie up enough resources to bring a server down.

Inbound connections never get made unless you've 'opened the port' by starting some daemon service. The bad guys are like vampires - they can't just break-in while you're not home, someone has to invite them in. So what daemons are you running ? mysql ? ssh ? ftp ? telnet ? We had someone on the forum the other day wanting to open port 631 (ipp) so he could print from the Internet.

Which options did you use with netstat ? With no parameters it will list lots of connections that are internal to your machine. You need only be concerned about tcp, udp and raw socket connections.

Oh, if you are editing posts under Iceweasel and you have NoScript running, you need to allow both knoppix.net and googleapis.com but it make editing bearable.