LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 04-16-2016, 08:32 PM   #1
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Rep: Reputation: 169Reputation: 169
Firewall


Quote:
Don't waste your time with configuring a firewall on Linux when it is a computer that is alway behind a firewall, such as your home PC behind your home router, or when you have no particularly important information on your laptop. If you keep the services that listen on the network to a minimum and have a decently secure password, you can forget your firewall. I personally have no personal computer, laptop or smartphone with a firewall running. I have, however, a home router with a well-configured firewall.
I have a DSL modem. Is that a time of router ?

I recall that the modem required a long number when I set it up.

WPA key
 
Old 04-16-2016, 08:45 PM   #2
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,801

Rep: Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140
You're best to tell us the brand/model details. Many units are combined modem router devices. If your computer gets a DHCP assigned local (private) IP address when you connect the unit, it is doing the routing to the internet. Does it have LAN ports?
 
Old 04-16-2016, 08:48 PM   #3
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,321
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
From whence cometh that quote?

A home consumer grade modem is generally not a firewall in any sense of the word. To be certain, you'd need to RTFM your own modem's manual.

You will sometimes see the term, "firewall router." In my experience, home "firewall routers" are not worth relying on. A home router is not at all in the same league as a firewall appliance.

What is commonly referred to as a "firewall router" is a firewall only in the sense that the public ip address is different from the the LAN ips on the devices behind it. If you have any open incoming ports on that "firewall router," for all practical purposes, it is not a firewall.

The WPA key is irrelevant. That is needed to establish your connection. Once the connection is established, it is available to be exploited.

Last edited by frankbell; 04-16-2016 at 08:53 PM.
 
Old 04-16-2016, 09:15 PM   #4
ardvark71
LQ Veteran
 
Registered: Feb 2015
Location: USA
Distribution: Lubuntu 14.04, 22.04, Windows 8.1 and 10
Posts: 6,282
Blog Entries: 4

Rep: Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842
Quote:
Originally Posted by Fixit7 View Post
I have a DSL modem. Is that a time of router ?
Hi Andy...

I wouldn't follow the advice you quoted. Firewalls are not foolproof.

Many DSL modems, like mine, are modem/router combos that includes its own firewall. If you can give us the brand and model (and model number) we might be able to help you configure it.

Regards...
 
Old 04-16-2016, 09:44 PM   #5
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
DLink by Verizon

DSL 2750 B

Puppy Linux has a firewall that uses Iptables, but I am currently not using it.
 
Old 04-16-2016, 10:21 PM   #6
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,321
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
Quote:
Puppy Linux has a firewall that uses Iptables, but I am currently not using it.
It may be pre-configured. Run this command

Code:
# iptables -L
to see the current settings.
 
Old 04-16-2016, 10:39 PM   #7
ardvark71
LQ Veteran
 
Registered: Feb 2015
Location: USA
Distribution: Lubuntu 14.04, 22.04, Windows 8.1 and 10
Posts: 6,282
Blog Entries: 4

Rep: Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842
Quote:
Originally Posted by Fixit7 View Post
DLink by Verizon

DSL 2750 B
Yes, your modem does have a built in firewall. Please see page 35 here to see how to set it up.

Regards...
 
Old 04-16-2016, 10:47 PM   #8
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
Thanks Ardvark.
 
Old 04-16-2016, 10:58 PM   #9
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
I am setup for Medium.

Will High let me still surf the net, email, etc ??

Quote:
Maximum Security High security level only allows basic Internet functionality. Only Mail, News, Web, FTP, and
(High): IPSEC are allowed. All other traffic is prohibited.

Typical Security Like High security, Medium security only allows basic Internet functionality by default.


(Medium): However, Medium security allows customization through NAT configuration so that you can
enable the traffic that you want to pass.

Last edited by Fixit7; 04-16-2016 at 11:01 PM.
 
Old 04-16-2016, 11:27 PM   #10
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,801

Rep: Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140
Yes. The firewall is to stop unwanted inbound access.
 
Old 04-16-2016, 11:40 PM   #11
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,801

Rep: Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140Reputation: 1140
A couple of simple online port scanning tools
http://www.t1shopper.com/tools/port-scan/
http://mxtoolbox.com/PortScan.aspx

Other tools offered
http://mxtoolbox.com/NetworkTools.aspx
 
Old 04-16-2016, 11:42 PM   #12
ardvark71
LQ Veteran
 
Registered: Feb 2015
Location: USA
Distribution: Lubuntu 14.04, 22.04, Windows 8.1 and 10
Posts: 6,282
Blog Entries: 4

Rep: Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842
Quote:
Originally Posted by Fixit7 View Post
I am setup for Medium.

Will High let me still surf the net, email, etc ??
You're welcome, Andy.

From what I see, there is no difference between the two in terms of default settings but the medium setting allows for "customization through NAT configuration."

Regards...
 
Old 04-17-2016, 08:01 AM   #13
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
Thanks gentlemen.
 
Old 04-17-2016, 10:33 AM   #14
ardvark71
LQ Veteran
 
Registered: Feb 2015
Location: USA
Distribution: Lubuntu 14.04, 22.04, Windows 8.1 and 10
Posts: 6,282
Blog Entries: 4

Rep: Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842
Quote:
Originally Posted by Fixit7 View Post
Thanks gentlemen.
You're welcome.

Regards...
 
Old 04-29-2016, 02:37 PM   #15
DJ Shaji
Member
 
Registered: Dec 2004
Location: Yo Momma's house
Distribution: Fedora Rawhide, ArchLinux
Posts: 518
Blog Entries: 15

Rep: Reputation: 106Reputation: 106
Quote:
Originally Posted by frankbell View Post
From whence cometh that quote?
hahaha Made me smile

Quote:
A home consumer grade modem is generally not a firewall in any sense of the word. To be certain, you'd need to RTFM your own modem's manual.

You will sometimes see the term, "firewall router." In my experience, home "firewall routers" are not worth relying on. A home router is not at all in the same league as a firewall appliance.

What is commonly referred to as a "firewall router" is a firewall only in the sense that the public ip address is different from the the LAN ips on the devices behind it. If you have any open incoming ports on that "firewall router," for all practical purposes, it is not a firewall.
But, most (all?) modem / router firewalls come with preset firewalls that block all incoming ports by default. Even those that don't, provide NAT for hooking up the LAN, so unless you configure explicit port forwarding, the local network is sealed off from the internet.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What firewall to use with VPS server that doesn't have stateful firewall matching Alan_SP Linux - Security 18 10-16-2015 08:40 AM
LXer: Managing A Single Firewall Policy For Multiple Servers Using Firewall Builder LXer Syndicated Linux News 0 12-06-2010 10:20 AM
router billion 5102 has firewall and software firewall tests aus9 Linux - Security 6 12-31-2006 10:09 PM
slackware's /etc/rc.d/rc.firewall equivalent ||| firewall script startup win32sux Debian 1 03-06-2004 09:15 PM
Firewall Builder sample firewall policy file ? (.xml) nuwanguy Linux - Networking 0 09-13-2003 12:32 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 08:37 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration