LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-05-2004, 10:56 AM   #1
infornography
Member
 
Registered: Oct 2003
Location: Australia
Distribution: Xubuntu 6.10
Posts: 73

Rep: Reputation: 15
Do I even need a firewall?


Hi,

I am running Slackware 10, with an ADSL connection. I keep my security patches up to date, and run no unnecessary services. When I do an "netstat -l" as root I get this:

Code:
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
udp        0      0 *:bootpc                *:*
I'm still new to this, but I think that means nothing is listening to the outside. So in a case like this, does a firewall make any difference?

I'm sorry if this is a dumb question, but I'm going in circles with the documentation.
 
Old 12-05-2004, 12:02 PM   #2
mikeyt_333
Member
 
Registered: Jun 2001
Location: Up in the clouds
Distribution: Fedora et al.
Posts: 353

Rep: Reputation: 30
yeah, you're right, there are no services running, no ports open etc... the bootpc that you see is for addressing etc... I wouldn't worry about a firewall right now, but it can never hurt. Of course it also depends on what purpose this system will serve. If you will have any important and sensitive information on this server, you definately should have a firewall installed. Just block packets with the syn flag set, and that way you can still do business with the outside world, but nobody can connect to you.

Mike.

P.S.
I'm not a firewall expert, but this is similar to my thinking over the years and it's been successful for me.

Last edited by mikeyt_333; 12-05-2004 at 12:05 PM.
 
Old 12-05-2004, 04:30 PM   #3
sigsegv
Senior Member
 
Registered: Nov 2004
Location: Third rock from the Sun
Distribution: NetBSD-2, FreeBSD-5.4, OpenBSD-3.[67], RHEL[34], OSX 10.4.1
Posts: 1,197

Rep: Reputation: 47
I would probably still run a firewall on it for the simple fact that if someone does gain access to the box, they'll have to root it to make use of it as an FTP server or anything like that (assuming you have a default deny policy on outbound traffic as well).
 
Old 12-05-2004, 09:33 PM   #4
m4dj4ck
Member
 
Registered: Aug 2004
Location: the coven
Distribution: slackies
Posts: 55

Rep: Reputation: 15
in this situation, i would still run a simple firewall( simple iptables script will do) and logs any incoming packets so that i can know what's the attacker are up to. It is OK if there's no firewall as long as you dont have any open ports or when you dont need NAT or Masq. Cheers!
 
Old 12-06-2004, 04:07 AM   #5
infornography
Member
 
Registered: Oct 2003
Location: Australia
Distribution: Xubuntu 6.10
Posts: 73

Original Poster
Rep: Reputation: 15
Thanks a lot for the advice everyone. I think I will add a basic firewall, better to be safe...
 
Old 12-06-2004, 11:31 AM   #6
mikeyt_333
Member
 
Registered: Jun 2001
Location: Up in the clouds
Distribution: Fedora et al.
Posts: 353

Rep: Reputation: 30
good call.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
BSD Firewall vs Linux Firewall ? rootlinux Linux - Security 5 08-29-2007 07:38 AM
Firewall lets ips which are not in the firewall ... why ? sys7em Linux - Networking 2 06-30-2005 12:50 PM
Firewall with features of a Sidewinder firewall? abcampa Linux - Security 4 04-22-2005 04:24 PM
slackware's /etc/rc.d/rc.firewall equivalent ||| firewall script startup win32sux Debian 1 03-06-2004 09:15 PM
Firewall Builder sample firewall policy file ? (.xml) nuwanguy Linux - Networking 0 09-13-2003 12:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration