LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-29-2008, 02:05 PM   #1
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Rep: Reputation: 41
IPtable consistancy/sanity checking software.


Hello all,

I am looking at doing some sort of automation for my firewall which is about 30 or so specialized rules in my iptables script. The problem is that I am not always around, when my fellow workers make rules they could make a error which may have consequences.

Are there any opensource utilities that do what I want?
 
Old 08-30-2008, 01:18 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
What kind of sanity checks are we talking about? Provide examples.

You could probably script some using shell scripts, depending on what you're after.

Last edited by win32sux; 08-30-2008 at 01:19 AM.
 
Old 09-02-2008, 05:29 PM   #3
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Original Poster
Rep: Reputation: 41
Looking for one that checks to see if there are overlaps in the actual firewall rules that could provide invalidity for a particular ruleset. Something similar to how some OS's have privilege checkers (Windoze for example)so there can be no escalation or accidental elevation in rights.

I looked and saw a number of white papers by a Dr. Wool, however, it looks like there isn't an actual application for this?
One would think the contrary since this would probably be very useful in the IT world.
 
Old 09-02-2008, 05:33 PM   #4
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Original Poster
Rep: Reputation: 41
A very simplistic example is as follows:

I have deny source 10.0.8.200 to 10.0.9.0/24 on the range of ports 20-25. Also includes broadcasts and multicasts.

Joe Blow decides hey, I'm going to circumvent this and allow a computer to do a broadcast from 8.x to the 9.x or a multicast. That there would then circumvent the first rule. Then Joe Blow allows another port which is included in the denies or allows and you can see where I am going with this....
 
Old 09-02-2008, 08:38 PM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
I've never used a program that does this sort of iptables checking, so I don't know. If I didn't want Joe Blow messing with my iptables setup then I simply wouldn't let him mess with it (instead of trying to detect when he does mess with it). I'm not saying "don't let Joe Blow use iptables", cuz I'm assuming you don't have a choice about that. But perhaps set up an iptables chain for him - a chain which he can mess with all he wants without being able to affect your other chains. This should be easy to do with sudo I think.

Last edited by win32sux; 09-02-2008 at 08:42 PM.
 
Old 09-03-2008, 10:14 PM   #6
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Original Poster
Rep: Reputation: 41
Mhh the reason being is for firewall testing without going too much into detail so joe blow doesn't pass something when he shouldn't if you know what I mean or fail pending on the point of view. Thanks for the suggestion, that helps me out in another avenue. I'll see what I can drum up in my spare time.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Checking for new versions of software introuble Programming 9 04-23-2006 06:10 PM
Security Checking Software Wibble Linux - Security 1 04-08-2004 10:27 AM
Checking software: PGP, MD5 etc.. tarballed Linux - Newbie 1 07-23-2003 01:22 PM
Checking software versions cav Linux - General 2 06-09-2003 01:24 PM
Checking Software? AMDPwred Linux - General 5 01-20-2002 11:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration