Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
04-11-2006, 12:19 AM
|
#1
|
Member
Registered: Jun 2005
Distribution: debian, ubuntu, redhat,knoppix
Posts: 194
Rep:
|
application layer firewall in linux?
HI,
I am looking for decent application firewall package. Can anyone give me some recommendation? I currently using iptables but it only does layer3 filter. I am looking for firewall can easily block messenger (or similiar chat program).
thx
chris
|
|
|
04-11-2006, 01:52 AM
|
#2
|
LQ Guru
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu
Posts: 9,211
Rep: 
|
you want to block by application rather than port/socket?
A simple google, or a repo check, will turn up a number of firewall tools, like firestarter and shorewall ... so distro and what you've tried would be good info here. I usd to use a commercial one: zonealarm ... at the time there was a linux varient (gratis for home use only) but, it seems, no more. However, if this is the sort of thing you want, have a look at:
http://www.linuxquestions.org/linux/...larm_for_Linux
|
|
|
04-11-2006, 01:59 AM
|
#3
|
Member
Registered: Jun 2005
Distribution: debian, ubuntu, redhat,knoppix
Posts: 194
Original Poster
Rep:
|
I thought both firestarter and shorewall are iptables based firewall which mean its only L3 packet filtering right (i presume they just add an GUI on iptables )? Zonealrm i never see before in linux port but will look up more although it appear to me more for workstation then a server (which is what i used).
Sorry that forgot to inc the distro i use. I am using debian sarge 3.1 .
|
|
|
04-11-2006, 02:40 AM
|
#4
|
LQ Guru
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu
Posts: 9,211
Rep: 
|
firestarter also lets you view and manage active processes via a gui - xchat is one of the examples used on the site: http://www.fs-security.com/
The link I sent you should be inspected too.
Quote:
It is well-known that firewalls can be loosely categorized into proxies and packet filters. The latter "know" the application-level protocols such as telnet, HTTP or SMTP and can inspect the protocol payloads and verify the commands. This comes at a significant performance penalty since packets have to be processed higher in the network protocol stack in application layer.
|
... if this sounds like what you would like. See: http://www.securityfocus.com/infocus/1531
It's just that when folk want application layer controls they are usually just wanting zone-alarm/windows style firewall interface.
|
|
|
04-11-2006, 04:54 AM
|
#5
|
Member
Registered: Apr 2006
Location: England
Distribution: Debian Sidux - openSUSE
Posts: 261
Rep:
|
Firestarter and Guarddog allow you to block certain protocols, which would allow you to block yahoo messenger and other chat programs.
There is one application based firewall for linux that I know of - TuxGuardian - http://tuxguardian.sourceforge.net/
Quote:
With TuxGuardian you'll be able to implement access control policies to the network resources in order to identify and control every application that tries to access the network.
|
I tried it many months ago and couldn't get the dependencies sorted out but I'm thinking of giving it another go.
Last edited by shame; 04-11-2006 at 04:55 AM.
|
|
|
All times are GMT -5. The time now is 12:42 PM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|