Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
03-02-2006, 01:04 AM
|
#1
|
LQ Newbie
Registered: Feb 2006
Posts: 1
Rep:
|
help me how to configure best firewall in linux
I m suffering a log n my network boz of lots of virues attcking in my network. That way most of the time my network get hang. I wnat to configure a firewall on linux pc. I have redhat Linux ES 4 edition. I dont know exectly how to configure firewall. I want nobody should able to access my network and dont want to allow download .exe, online music and pron site. I also wana restrict abuse or any type of thread to enter into my network. I want to know, if too much broadcasting in my network so how can i control via iptables or else.
Pls help me. if u have any solution so pls mail me at rock_micro2004@yahoo.com
Thank you
Akhil
|
|
|
03-02-2006, 02:39 AM
|
#2
|
Member
Registered: Feb 2006
Location: Vietnam
Distribution: FC , RH , SuSE
Posts: 106
Rep:
|
Quote:
I want nobody should able to access my network and dont want to allow download .exe, online music and pron site.
|
If nobody can access your network he can not do anything (include downloading) , and then your network is invisible to everyone . Are your sure that you want it .
This is command deny all connections to your system :
iptables -I INPUT -i <your NIC such as eth0> -j DROP .
Last edited by nguyennh; 03-02-2006 at 02:41 AM.
|
|
|
03-02-2006, 03:00 AM
|
#3
|
Senior Member
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141
Rep: 
|
You can use iptables to do this. Although it's not complicated, you do need to spend some time planning which traffic you want to allow into and out of your network as well as which traffic you want to keep out. I'd recommend doing some reading first - there are plenty of good references around. Places like the netfilter documentation page at http://www.netfilter.org/documentation/index.html and Arno's iptables page at http://rocky.eld.leidenuniv.nl/ are useful.
Please don't ask for email responses - the debate and solution of problems should be here for everyone to see... 
|
|
|
03-02-2006, 07:42 AM
|
#4
|
Member
Registered: Jan 2006
Location: Vancouver BC
Distribution: LFS, SLak, Gentoo, Debian
Posts: 291
Rep:
|
Three resources specific to building a good iptables firewall, two are blog entries and one is an article.
1) Apotheon's Blog entries
2) The Article
You may need to sign up for a free membership to view the entries.
|
|
|
03-02-2006, 06:28 PM
|
#5
|
Member
Registered: Aug 2003
Location: Omaha, Nebraska
Distribution: Red Hat, Fedora, Debian
Posts: 65
Rep:
|
A simplier approach for you may be to install IPCop or Red Wall
http://www.redwall-firewall.com/
http://www.ipcop.org/
If you are going to run a full distro as a firewall look at Firestarter. Its a GUI for the iptables
http://www.fs-security.com/
Last edited by crimsontide; 03-02-2006 at 06:30 PM.
|
|
|
All times are GMT -5. The time now is 07:04 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|