LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-14-2004, 03:49 PM   #1
Trano
Member
 
Registered: Jul 2004
Posts: 30

Rep: Reputation: 15
Dynamic Firewall


I have a fedrora core 2 system running as a router, firewall, and proxy server. I have the squid proxy configured using an external ACL to redirect to a terms of service page until the user has accepted them.

I want to be able to block all ports instead of just http until the user has accepted the terms. Currently I am using shorewall as the firewall.

Is there anyway to dynamically update shorewall to block all ports except the transparent proxy redirect of port 80 to port 3128 for all users and then add certain users that are allowed full access?
 
Old 08-17-2004, 08:23 AM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
I would imagine it's better to have the ACL referenced from the ports you want to control,
using port re-direction to move outgoing request to the proxy, ie transparent,
rather than closing the ports and forcing auth only on 80

There is a patch-o-matic patch for netfilter & iptables called condition
I use it to check a dynamically stored variable, eg after a successful pam auth, an OK value (1) is written to /proc/net/ipt_condition/web_ok/192.168.1.21/ to signify that ip is allowed to pass web traffic
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Dynamic name resolution for dynamic IP merlin740 Linux - Software 2 10-04-2004 05:56 PM
FreeBSD firewall and dynamic IP-address Mikessu *BSD 3 04-19-2004 10:33 AM
Dynamic DNS and stale firewall lookups socom Linux - Networking 2 02-28-2004 08:21 PM
Firewall Builder sample firewall policy file ? (.xml) nuwanguy Linux - Networking 0 09-13-2003 12:32 PM
Dynamic Firewall Rules DavidPhillips Linux - General 2 12-06-2001 06:41 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:38 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration