LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-20-2015, 09:16 AM   #1
Biosko
LQ Newbie
 
Registered: Nov 2012
Posts: 9

Rep: Reputation: Disabled
Lightbulb Administration of all incoming / outgoing traffic ideas


Hello,

I would like to set up a firewall solution into my network.

The idea is to block all internet traffic (incoming/outgoing) and only use white-list for approved connections.

The question is how to handle it?

I thought about iptables rules. Block everything, log blocked traffic and allow which is needed.
This should work OK for programs/daemons.

Problem is how to handle http/https traffic. There is endless list of http pages also many are using CDN for content so it will be very hard to just allow and maintain white-list of ips.

How do you usually handle this? Maybe squid? Can you give me some ideas please?

The idea is not about restrict some content to users but be in control of incoming and outgoing traffic.

Thank you!
 
Old 08-20-2015, 03:57 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by Biosko View Post
The idea is to block all internet traffic (incoming/outgoing) and only use white-list for approved connections. (..) Problem is how to handle http/https traffic. There is endless list of http pages also many are using CDN for content so it will be very hard to just allow and maintain white-list of ips. (..) The idea is not about restrict some content to users but be in control of incoming and outgoing traffic.
If you want total control then having to approve connections is just the thing you'll have to live with. Can't have it both ways. More importantly, what you forgot to explain are the reasons why you would want total control...
 
Old 08-20-2015, 05:24 PM   #3
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by Biosko View Post
There is endless list of http pages also many are using CDN for content so it will be very hard to just allow and maintain white-list of ips.
All the IPs should be YOUR CDN Provider's.
Not so hard to maintain.
Why do you say it will be "very hard" to maintain a whitelist of known and approved IPs?
 
  


Reply

Tags
firewall, network, security, traffic



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Rotuing Gameserver Traffic thorugh VPN Incoming/Outgoing tilloo3 Linux - Networking 11 05-25-2015 09:20 AM
Routing return traffic based on the NIC of the incoming traffic? adamk75 Linux - Networking 3 12-11-2011 04:27 AM
Traffic shaping (limiting outgoing bandwidth of all TCP-traffic except FTP/HTTP) ffkodd Linux - Networking 3 10-25-2008 12:09 AM
Network traffic -- monitor my incoming and outgoing ports bskrakes Linux - Networking 5 04-02-2008 08:44 AM
Incoming and outgoing traffic (packets) increased tooparam General 4 09-22-2006 01:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration