LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Fedora
User Name
Password
Fedora This forum is for the discussion of the Fedora Project.

Notices


Reply
  Search this Thread
Old 07-12-2005, 08:08 AM   #1
alesz
Member
 
Registered: Mar 2005
Distribution: FC5 on disk, Knoppix as LiveCD
Posts: 48

Rep: Reputation: 15
firewall: prevent some applications access internet


using iptables, can i prevent some selected applications to access internet?
or can i do it using some other security tool?

i know about the incomming traffic firewall (or hosts.deny, hosts.allow), if i have deamon, such as webserver, ftp or ssh, but my problem is turned around - accessing internet from within should be denied.

for example, i would like to prevent openoffice accessing internet.
can i select, that only gaim, akregator, konqueror and yum are allowed to access internet (eth0), without writing my own kernel module?
 
Old 07-12-2005, 08:28 AM   #2
ethics
Senior Member
 
Registered: Apr 2005
Location: London
Distribution: Arch - Latest
Posts: 1,522

Rep: Reputation: 45
Guarddog is a firewall app that uses IPtables but can block individual apps from the net, i didn't like it that much, i use firestarter, but you might

http://www.simonzone.com/software/guarddog/
 
Old 07-12-2005, 08:54 AM   #3
alesz
Member
 
Registered: Mar 2005
Distribution: FC5 on disk, Knoppix as LiveCD
Posts: 48

Original Poster
Rep: Reputation: 15
thanks for answering, i didn't know about guarddog, i'll put it to use at some later time, it looks great.

as i've understood, guarddog supports only protocol-level firewall, not application-level (e.g. bound to PID or command name).

i like the firestarter app... it even acts as IDS.

is it possible to restrain internet access using application names, such as inetd services in hosts.deny, where i can specify IP's for sshd different from httpd.
there is only one "/usr/bin/konqueror", and could i restrain my internet access rule to this command name? perhaps, can i use SElinux to specify something like that?

once again: i would like to specify applications, that can access internet. they could all just access port 80, using http protocol, so using protocol they are indistinctable.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux router/firewall box for shared Internet access from 3 separate LANs? dan.patton Linux - Networking 4 04-15-2006 05:37 PM
Prevent Root access with SSH rshooper Linux - Security 4 11-18-2004 01:05 PM
IPTables Scripts Won't allow Firewall Internet Access rootking Linux - Networking 3 09-12-2004 02:50 PM
Unable to access internet after setting Firewall? novkhan Linux - Networking 1 04-26-2004 11:50 AM
Access my box from internet ? CISCO + firewall johnecobo Linux - Security 1 12-11-2002 03:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Fedora

All times are GMT -5. The time now is 06:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration