LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-14-2007, 06:19 PM   #1
resonator
LQ Newbie
 
Registered: Dec 2006
Location: new zealand
Distribution: fedora
Posts: 2

Rep: Reputation: 0
should i trust lokkit to do a good job?


im a noob

Ive just got my Fedora server to act as a gateway for my XP laptop by using lokkit. It works fine but im not sure if its secure or not.

Can someone please tell me if there is some glaring hole or im just paranoid and should marvel the extreme holiness of the linux box.

On the linux box eth0(dhcp) is to my adsl, eth1(192.168.0.1) is to the xp laptop(192.168.0.2)

During lokkit i chose to trust and masquerade eth1 for the gateway

# Firewall configuration written by system-config-securitylevel
# Manual customization of this file is not recommended.
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -i eth1 -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp --icmp-type any -j ACCEPT
-A RH-Firewall-1-INPUT -p 50 -j ACCEPT
-A RH-Firewall-1-INPUT -p 51 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp --dport 5353 -d 224.0.0.251 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 631 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 443 -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited
COMMIT
*mangle
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -i eth1 -j MARK --set-mark 0x9
COMMIT
*nat
:PREROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -m mark --mark 0x9 -j MASQUERADE
COMMIT

any help would be much appreciated.
cheers
 
Old 01-15-2007, 10:23 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Frankly it's better than no firewall, but it certainly could be more secure in my opinion.

A better way to start out is to tell us what services/ports do you need? Do they need to be accessible to the firewall box, LAN, or both? What do you need ports 50 and 51 for? A VPN? What about the CUPS/IPP port (631)? Is there a printer attached directly to the firewall box? Is it acting as a print server?

BTW, welcome to Linuxquestions.

Last edited by Capt_Caveman; 01-18-2007 at 08:05 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Too good of a job cloning a system Randux Slackware 7 01-11-2007 04:09 PM
2006B3 :) good job crAckZ Mandriva 1 08-29-2005 11:09 PM
Is there anything else like lokkit? Rotwang Linux - Networking 3 05-28-2004 12:15 PM
Lokkit stew Linux - Networking 3 05-23-2003 10:01 AM
Bypassing lokkit, gnome-lokkit and redhat-config-securitylevel on RedHat 8.0 Son77 Linux - Security 3 10-18-2002 03:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration