LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-09-2005, 03:27 AM   #1
pingu
Senior Member
 
Registered: Jul 2004
Location: Skuttunge SWEDEN
Distribution: Debian preferably
Posts: 1,350

Rep: Reputation: 127Reputation: 127
Securing server - SELinux or iptables or both?


I'm setting up a samba-server, FC4, serving two subnets in a school.
Now I have a small question about setting up security: basically the question is "Should I use iptables (no rules at the moment) or SE-Linux (which is active), can I use both or will I end up with a complete confusion?
What I need to do is to separate these subnets, no traffic whatsoever allowed between them.
The smb.conf controls access to shares, but I need to block everything else.
I have used/configured iptables before but never SE-Linux, meaning I'll be up-and running faster if I configure iptables only (leaving SE-Linux at default config).

(edit)
I should add that the networks resides behind a few firewalls adminstered by the "county" - I need no protection against outside, only against our own users (mainly the students).

Last edited by pingu; 11-09-2005 at 03:31 AM.
 
Old 11-09-2005, 09:21 PM   #2
brianthegreat
Member
 
Registered: Oct 2005
Posts: 518

Rep: Reputation: 32
If your sitting behind a firewall and not worried about being hacked from the inside then the heck with IP Tables. Now, if people are going to be accessing the server from the outside then ip tables are a must regarding limiting what users can access. This can turn into a complex problem really fast regarding exactly what you are trying to do.

Last edited by brianthegreat; 11-09-2005 at 10:24 PM.
 
Old 11-10-2005, 04:07 AM   #3
pingu
Senior Member
 
Registered: Jul 2004
Location: Skuttunge SWEDEN
Distribution: Debian preferably
Posts: 1,350

Original Poster
Rep: Reputation: 127Reputation: 127
Thing is, I need to block all traffic between our two subnets.
We are strictly forbidden to allow any traffic between 'students' and 'staff' networks.
You say:
Quote:
ip tables are a must regarding limiting what users can access
As I understand you, SELinux doesn't really handle access-rights, it is a complement to firewalls not just a more advanced one.
The little I've had time to read about SELinux I think that's correct, it's iptables I need.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mail server grsecurity-selinux zuessh Linux - Security 1 04-26-2005 01:52 PM
Securing System: Snort, IPTables, Logging Matir Linux - Security 1 11-29-2004 03:06 PM
securing using firestarter or iptables PennyroyalFrog Linux - Security 3 10-13-2004 01:36 PM
Securing iptables kola Linux - Security 20 09-13-2004 03:28 AM
Securing Server brentos Linux - Security 4 06-08-2004 10:57 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration