LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-22-2005, 09:02 AM   #1
massysett
LQ Newbie
 
Registered: Nov 2005
Location: Silver Spring, Maryland USA
Distribution: SUSE Linux 10.0
Posts: 17

Rep: Reputation: 1
Firewall that automatically changes inbound rules


I have a laptop. When I use it at home, it connects to my WPA wireless router. This is a secure environment (secure enough for my purposes, anyway) and when I'm at home I want my laptop to allow inbound SSH connections so that my desktop can access it.

On the other hand, when I'm using my laptop away from home, I don't want anything to be able to access it.

Is there a firewall that will automatically change inbound permissions based on what wireless access point I am connected to? It would be great if I could say "allow inbound SSH and NFS when I am connected to a wireless access point with this SSID and this WPA password. Otherwise, don't allow anything inbound."
 
Old 11-22-2005, 12:27 PM   #2
genlee
Member
 
Registered: Jul 2003
Distribution: Solaris 8/9, gentoo
Posts: 41

Rep: Reputation: 15
I don't know how well this will work but you could try it. Setup a rule to allow inbound nfs and ssh to whatever network your wireless router uses for dhcp. You could try using an obscure network address on your router so you have less of a chance of having another wap assign you an ip from that network.
 
Old 11-23-2005, 11:31 AM   #3
massysett
LQ Newbie
 
Registered: Nov 2005
Location: Silver Spring, Maryland USA
Distribution: SUSE Linux 10.0
Posts: 17

Original Poster
Rep: Reputation: 1
Quote:
Originally posted by genlee
I don't know how well this will work but you could try it. Setup a rule to allow inbound nfs and ssh to whatever network your wireless router uses for dhcp. You could try using an obscure network address on your router so you have less of a chance of having another wap assign you an ip from that network.
Thanks. I've been looking at the iptables documentation. I'm thinking what I'll try is to set up rules that block all incoming traffic unless it comes from a computer with my desktop machine's IP address and MAC address. IP address filtering wouldn't be enough on its own because when I take the laptop on the road, another machine might have the same IP address on the network (192.168.x.x). And of course MACs can be spoofed. But put these two together and I should have a secure setup (combined of course with making sure the SSH and NFS is secure.)
 
Old 11-24-2005, 10:31 AM   #4
massysett
LQ Newbie
 
Registered: Nov 2005
Location: Silver Spring, Maryland USA
Distribution: SUSE Linux 10.0
Posts: 17

Original Poster
Rep: Reputation: 1
Alright, so I wrote a scrit and it seems to work pretty well. I've got the source code here if you need a similar setup:

http://www.smileystation.com/laptopwall.php
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DHCP firewall rules mullog Linux - Networking 1 04-24-2005 11:52 PM
Resetting ALL Firewall rules RemusX2 Linux - Software 1 02-28-2005 07:18 AM
Firewall Rules studpenguin Linux - Security 0 07-01-2004 03:14 AM
help with firewall rules please deuce868 Linux - Security 1 06-14-2004 03:18 PM
RH8 - how to automatically run iptables rules shell script at boot time nu-B Linux - General 1 10-29-2003 08:38 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration