LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 07-05-2008, 01:21 AM   #1
PKumar
LQ Newbie
 
Registered: Jun 2007
Posts: 11

Rep: Reputation: 0
Firewall to monitor visited sites by user's


Hi,

I am working as system administrator, In office, there is workstation using Windows NT and one Linux server which connects all workstations to Internet.

ex :
Workstation W1, W2 , W3 .... Wn connected to Linux server L1 (Using LAN) which is connected to Internet. So all traffics on Linux server comes from LAN on eth1 forwarded to eth0 which is connected to internet.

Now problem, I want to monitor from which workstation accessed which website , since all traffic passes through Linux server so I think its possible to do.

I am looking for some software or others using which I can do.

Thanks
 
Old 07-05-2008, 01:39 AM   #2
Mr. C.
Senior Member
 
Registered: Jun 2008
Posts: 2,529

Rep: Reputation: 63
Monitor, as in maintain logs? Or block?

Consider DansGuardian, Squid, Snort
 
Old 07-05-2008, 05:59 AM   #3
PKumar
LQ Newbie
 
Registered: Jun 2007
Posts: 11

Original Poster
Rep: Reputation: 0
Quote:
Monitor, as in maintain logs? Or block?

Currently I am looking for monitor, but If its create log and using this I can block the sites that will very excellent.

Thanks
 
Old 07-05-2008, 12:30 PM   #4
Mr. C.
Senior Member
 
Registered: Jun 2008
Posts: 2,529

Rep: Reputation: 63
This can be solved at so many levels. Many firewalls come with URL filtering/logging, or you can add/install something like snort in log-only configuration.

Or, if you control a gateway machine, you install tcpdump, and use wireshark to periodically check http traffic sites.

Lots of options...

Last edited by Mr. C.; 07-05-2008 at 12:32 PM.
 
Old 07-06-2008, 11:46 PM   #5
PKumar
LQ Newbie
 
Registered: Jun 2007
Posts: 11

Original Poster
Rep: Reputation: 0
Some one suggested me smoothwall Any idea how is it?
 
Old 07-07-2008, 12:11 AM   #6
Mr. C.
Senior Member
 
Registered: Jun 2008
Posts: 2,529

Rep: Reputation: 63
That might have been me. I've been using one for over 5 years.
 
Old 07-07-2008, 11:58 PM   #7
PKumar
LQ Newbie
 
Registered: Jun 2007
Posts: 11

Original Poster
Rep: Reputation: 0
Wow! Great,
Quote:
In office, there is workstation using Windows NT and one Linux server which connects all workstations to Internet.

ex :
Workstation W1, W2 , W3 .... Wn connected to Linux server L1 (Using LAN) which is connected to Internet. So all traffics on Linux server comes from LAN on eth1 forwarded to eth0 which is connected to internet.
do you thinks its fit in my network infrastructure?
 
Old 07-08-2008, 12:19 AM   #8
Mr. C.
Senior Member
 
Registered: Jun 2008
Posts: 2,529

Rep: Reputation: 63
Yes, it will work fine.

I would recommend a modification (assuming you use the Linux server for other duties).

Get another PC in which to install smoothwall 3 express. You will use *that* as your router, and leave your other Linux station to do whatever you want. Your config is straightforward. It will look like this:

Code:
                                           +--- PC1
                                           |
                     +---  LAN  --- switch +--- PC2
                     |                     |
Internet --- Smoothwall                    +--- PC3
                     |                     |
                     +---  DMZ +           +---.PCN
                               |
                               |
                               + Linux server
The smoothwall station will need 2 or 3 network cards. One for the Internet (called the Red interface), one for the LAN interface (green), and one more optional interface for a DMZ (orange). Actually, you can have yet a fourth card, for a wireless or other network (blue, for guests, etc.). Place a switch on each interface (I didn't show one on the DMZ), as many network cards don't work well card <-> card.

I placed your Linux machine as a server on the DMZ, but it can go on the LAN if you'd like.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall Monitor Peter_APIIT Linux - Software 3 07-11-2007 02:35 AM
Moz & FF cannot access secure sites behind firewall rickenbacherus Linux - Networking 2 11-05-2004 11:54 AM
newbie: how to monitor other user's job when in root ? sirpelidor Linux - Newbie 3 06-23-2004 02:15 PM
Can't get to certain ftp sites through my firewall Stric-9 Linux - Newbie 2 11-23-2003 12:10 PM
Firewall / Network Security Test Sites mrnikeswsh Linux - Security 1 08-28-2003 04:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration