LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions
User Name
Password
Linux - Distributions This forum is for Distribution specific questions.
Red Hat, Slackware, Debian, Novell, LFS, Mandriva, Ubuntu, Fedora - the list goes on and on... Note: An (*) indicates there is no official participation from that distribution here at LQ.

Notices


Reply
  Search this Thread
Old 04-20-2005, 06:48 PM   #1
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
Monowall Question


Recently switched firewall from Smoothwall to IP Cop but not happy about IP Cop firewall responding to pings even though all ports closed.

However now looking at using Monowall, so my Q is this
In smoothwall there is a facility to drop ICMP, IGMP pings and something to do with SYN cookies.

How does one do this with Monowall.
( yes I have RTFM, but I dont really understand how Monowall does this )

floppy
 
Old 04-22-2005, 10:08 PM   #2
ghight
Member
 
Registered: Jan 2003
Location: Indiana
Distribution: Centos, RedHat Enterprise, Slackware
Posts: 524

Rep: Reputation: 30
I usually heavily discourage people from doing any of these unless they have a specific reason for doing so. Turning these options on (or off depending on how you look at it) should only be used in response to certain attacks on your routers or firewalls. Turning them on all the time can cause all kinds of random annoying problems that you may or may not notice.

A point to think about here is if they really felt these options would be beneficial to the Internet community, why wouldn't they default to "off" ? In my experience, don't bother turning them off unless you are being attacked.
 
Old 04-23-2005, 01:25 AM   #3
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643

Original Poster
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
I am on dial-up, which means I have a different IP address everytime on the net. However I am usually on the net for up to 4 -5 hours per day.

In my snort logs on an average day I would usually be scanned by some idiot using Cyberkit or nmap - four or five times at least, so I would consider running in true stealth to be very beneficial.
Responding to pings is not my idea of stealth.

Browsing through the Security forum here at LQ, one sees a lot of people complaining of being cracked, I really don't intend to be one of them if I can avoid it. In my experience enabling these options before you are attacked is better than picking up the pieces later.

floppy
 
Old 04-23-2005, 07:59 AM   #4
simon_w
Member
 
Registered: Jun 2004
Location: UK
Distribution: Debian Etch
Posts: 71

Rep: Reputation: 15
Couldn't you just manually modify the firewall rules script to drop ICMP traffic?
 
Old 04-23-2005, 11:07 AM   #5
ghight
Member
 
Registered: Jan 2003
Location: Indiana
Distribution: Centos, RedHat Enterprise, Slackware
Posts: 524

Rep: Reputation: 30
Again, I know I'm not answering the original question, but I think a little more study on why these options exist in the first place would really help further my point. "Stealth" doesn't mean a whole lot when there are 50 other way of verifying that something exist at the other end of the line. ICMP responses are valuable to your ISP and may be required by many services you HAVE requested such as online gaming plus a hundred other things. If you provide ZERO services from your network, there is no difference between "stealth" and "closed" ports.

To try to answer the question, each of these options are easily added my typing them in to the command line. I would guess that the IPCop developers are smart enough to know when these services are valuable and when they aren't so it's possible they set them automatically. Just a guess.

Again, I'm certainly not trying to get under your skin by my responses. Just remember that if you have issues with certain sites or services, these should be on your lists of things to remember.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Question, Apples Contribution to Open Source + MacOs file structure question Higgy3k Other *NIX 5 07-25-2005 04:23 AM
Not your regular GRUB question - just a short question for a fried MBR!! ziphem Linux - General 3 01-31-2005 01:51 PM
login prompt question & kde scheme question JustinCoyan Slackware 2 06-09-2004 02:02 PM
Monowall satimis General 2 04-17-2004 11:46 PM
samba smb.config question (quick question) TheDOGG Linux - Networking 1 03-02-2004 07:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions

All times are GMT -5. The time now is 02:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration