LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-22-2009, 01:15 PM   #16
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380

Quote:
Originally Posted by Completely Clueless View Post
But with a policy of "ACCEPT 0 packets" of INPUT I can't see how this can possibly work?? Can it?
It's not saying "ACCEPT zero packets". It's saying "the policy is set to ACCEPT, and it has been enforced on zero packets". In your case, with the rules you implemented, no packet should ever run into the policy for that chain, since the last rule in the chain matches any packet and sends it to DROP. An alternative to the way you have it set would be to eliminate the last rule and change the policy to DROP. That can, however, be more risky for you since you might flush the chain without resetting the policy and thus lock yourself out of your own box. So the way you have it now is just fine.

Quote:
As an aside, I think this is one area of the Ubuntu distro that Team Ubuntu needs to look into urgently if they hope to lure away more Windoze users. Iptables may certainly be a powerful, versatile and wonderfully precise way of tailoring your firewall needs, but user-friendly it CERTAINLY AINT!

I'm aware of add-ons like lokkit and ufw that simplify firewall rule-setting, but they're still crude and in need of further refinement - and they don't come with the distro so you have to download them, which is kinda risky with no operational firewall in the first place!!
There's many more GUI front-ends out there designed specifically for making this user friendly. I suggest you have a look and see cuz you might find something that suits your needs, and there might be a package for it readily available in the Ubuntu repositories.

Last edited by win32sux; 01-22-2009 at 01:24 PM.
 
Old 01-23-2009, 02:34 AM   #17
Completely Clueless
Member
 
Registered: Mar 2008
Location: Marbella, Spain
Distribution: Many and various...
Posts: 899

Original Poster
Rep: Reputation: 70
Quote:
Originally Posted by win32sux View Post
There's many more GUI front-ends out there designed specifically for making this user friendly. I suggest you have a look and see cuz you might find something that suits your needs, and there might be a package for it readily available in the Ubuntu repositories.
I would suggest Team Ubuntu check out how Team Knoppix have approached the problem. Knoppix comes with a highly configurable firewall built-in from the get-go. What's more it's suitable for beginners and experts alike to configure; one can go into as much detail as one is comfortable with. I wouldn't be using Ubuntu at all but for the fact that its bang-up-to-date kernel sees and fires up my usb stick modem with zero messing around. Ubuntu's a thoroughly good distro, but none of them are perfect, and this issue of firewalling is where Ubuntu badly falls down, IMHO.
THanks for your comments.

CC.
 
Old 01-23-2009, 03:43 AM   #18
Completely Clueless
Member
 
Registered: Mar 2008
Location: Marbella, Spain
Distribution: Many and various...
Posts: 899

Original Poster
Rep: Reputation: 70
Quote:
Originally Posted by rweaver View Post
Don't get me wrong-- a firewall is a very useful piece of technology to have between you and the internet. That being said a firewall on the local machine is largely moot if you're already NAT'd like most people on broadband. If you get a direct routeable internet ip on your computer it's considerably more useful of course.
Sorry I must have missed this first time around. I'm not NAT'd as there's no internal network. I'm just a dabbler at home with seperate boxes running 3 totally seperate broadband lines (for security reasons). From my first post:

"The box is a stand-alone desktop, single-user, running Ubuntu 8.1; no server requirements; no SSH etc."

CC.
 
Old 01-23-2009, 07:56 AM   #19
rweaver
Senior Member
 
Registered: Dec 2008
Location: Louisville, OH
Distribution: Debian, CentOS, Slackware, RHEL, Gentoo
Posts: 1,833

Rep: Reputation: 167Reputation: 167
Quote:
Originally Posted by Completely Clueless View Post
Sorry I must have missed this first time around. I'm not NAT'd as there's no internal network. I'm just a dabbler at home with seperate boxes running 3 totally seperate broadband lines (for security reasons). From my first post:

"The box is a stand-alone desktop, single-user, running Ubuntu 8.1; no server requirements; no SSH etc."

CC.
If you have no outward facing services a firewall is pretty useless (as far as "protecting" you from something goes at least.) unless you want to do something like drop icmp.

If you're not running ssh, ftp, telnet, or other daemons that are listening on outside ports... there's nothing anyone can do to get access to your system.

Out of curiosity, can you give us the output of a netstat -pan?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DNSBL blocks and iptables fukawi2 Linux - Networking 2 10-26-2008 06:57 PM
work firewall blocks ssh traffic c_mitulescu Linux - Networking 3 07-12-2006 01:44 PM
Firewall blocks Samba? IchBin Linux - Networking 1 06-11-2005 05:21 PM
SuSE 9.2 - firewall blocks internal network cannabuz Linux - Networking 0 01-17-2005 08:34 AM
Firewall blocks me from sending irc dcc. zer0python Linux - Networking 8 01-13-2004 09:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration