LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 11-08-2001, 07:31 AM   #1
Artman
LQ Newbie
 
Registered: Nov 2001
Posts: 3

Rep: Reputation: 0
Win XP gateway security strategy


Hi,
My home network consists of 2 computers: a Linux and a Win XP. Due to hardware restrictions, the Win XP will act as an internet gateway (dial-up PPP account). I'm currently running Norton Personal Firewall on this box.

My question concerns the Linux box: do I need to install a firewall here eventhough I already have one in XP? Should I be worried about closing off ports for telnet, ftp, etc? I'm the only user in this little network.
Thanks,
Art
 
Old 11-09-2001, 10:18 PM   #2
tarballedtux
Member
 
Registered: Aug 2001
Location: Off the coast of Madadascar
Distribution: What's the difference? It's Linux.
Posts: 497

Rep: Reputation: 30
Hmmm...

Although I'm completely against using Micro$oft as a security product, you should limit connections, including:


telnet (if you don't use it)
ftp (if you don't use it)
I personally take all ICMP packets out, that stops alot of funky script kiddying.
if you get deep into the ipcains jungle, consider not allowing SYN flagged packets on the inbound at all unless you explicitly allow want them.


If tyhis helps (YEAH!)
If not post again for a refined reply
 
Old 11-10-2001, 02:04 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,610
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
uhm, that's understandable, about the ICMP part, but It's gonna break stuff.
Try allowing all types outbound, but inbound only type's 0,3,4,5,9,12,14.
 
Old 11-10-2001, 10:52 AM   #4
[BHBS]=TK
Member
 
Registered: Aug 2001
Location: Salt Lake City, UT
Distribution: REDHAT 7.1
Posts: 32

Rep: Reputation: 15
The answer to your question depends on what you plan to be doing. Are you going to run the XP box or the Linux box with any server capabilites?
If you are going to run them as workstations, just disable ICMP requests and you should be relatively invisible to the rest of the world.
If you are going to run services , then which ones?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall Security / Gateway Routing colabus Linux - Networking 1 09-13-2005 11:15 PM
Firewall Security / Gateway Routing colabus Linux - Security 3 09-09-2005 06:40 PM
Interesting Security Strategy junkken Linux - Security 3 02-03-2005 07:39 AM
Odd problem: Gateway unreachable after certain amount of time (Win XP Gateway) SocialEngineer Linux - Networking 2 08-13-2004 12:54 AM
gateway access security? andzerger Linux - Networking 4 02-20-2004 01:01 AM


All times are GMT -5. The time now is 12:10 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration