LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-11-2005, 09:49 AM   #1
kunal_bhattacharya
LQ Newbie
 
Registered: Jul 2005
Location: india
Distribution: rhel -3
Posts: 2

Rep: Reputation: 0
In need of firewall codes on iptables


I'm trying to code a firewall in linux using iptables, for a wireless lan network as a project. I'm still new to networking, so I would be thankful if somebody could help me out in framing a good firewall policy. I'm searching some codes on iptables which would help me get the right kind of firewall i need.




any kind of suggestions or views will be welcome .
mail: kunal_bhttchrya@yahoo.com
 
Old 07-11-2005, 11:34 AM   #2
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
You might want to ask the mods to move this to the Security forum as you'll probably get better advice there. As far as iptables is concerned, a wireless interface is no different from a wired one.

Really the best way to start with iptables is to set all of your defaults to DROP so that your computer is completely isolated from the net and then start setting rules that allow the kind of traffic that you're willing to have. Just remember that iptables rules are executed in order and the packet is handled according to the first rule that matches. Without more specifics on the kinds of things you are trying to do with this firewall, it won't be easy to make suggestions about how to write one. However, I would spend some serious time searching here at LQ as I know there is a lot of advice on writing good iptables firewalls. The Security forum is going to be your best bet.
 
Old 07-11-2005, 12:35 PM   #3
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
Moved: This thread is more suitable in Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
Old 07-11-2005, 05:08 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
This is one of my favorite tutorials, which includes a number of example firewalls
http://iptables-tutorial.frozentux.n...-tutorial.html

Here is a little more simplistic example for a single host firewall:
http://www.linuxquestions.org/questi...60#post1284560

Wireless networks pose an interesting problem for firewall design. An unsecured or even a secured link using one of the weaker encryption implementations (WEP and some WPA) absolutely require that you treat them like an untrusted DMZ. Personally I would consider all wireless networks to be inherently untrusted regardless of the encryption technology used. Putting some thought into the physical design of your network can go a long way in easing some of the firewalling headaches. For example just plugging a wireless AP into your trusted network is a major no-no, not only because you may be broadcasting sensitive information, but you also may be providing a means of circumventing your perimeter firewall.
 
Old 07-13-2005, 04:17 PM   #5
kunal_bhattacharya
LQ Newbie
 
Registered: Jul 2005
Location: india
Distribution: rhel -3
Posts: 2

Original Poster
Rep: Reputation: 0
the "fire wall"

I thank you all for the suggested links specially the one on the iptable tutorial.
I finally have most of the rules configured and tested.

I wanted to post all the rules I coded, but i'll do so in the next reply, I would like to suggest a page where i found the solutions to most of my problems, http://www.linuxhelp.ca/guides/iptables/iptables-script

I hope this helps others like me who are searching for simple rules to apply on their firewall servers (I did this just as a part of a project )
 
Old 07-14-2005, 02:38 PM   #6
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Quote:
I wanted to post all the rules I coded, but i'll do so in the next reply, I would like to suggest a page where i found the solutions to most of my problems, http://www.linuxhelp.ca/guides/iptables/iptables-script
I still prefer the tutorial script; much easier to modify and uses fewer of the cumbersome rules your recommended one uses.
There are scripts available that also add sysctl entries, but these are bordering on paranoid security levels.
I would always recommend starting with a minimal ruleset until you can understand it fully.
eg There is a very good reason for loading the filter table rules first..
Then of course the sky is the limit..
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables with iptables-firewall.conf arno's matt3333 Slackware 16 06-28-2007 07:20 AM
Are the hex codes for colors in a jpg the same codes as used in html? abefroman Linux - Security 3 07-31-2005 03:21 PM
IPTABLES firewall Vs rc firewall netguy2000 Linux - Security 7 02-28-2004 04:31 AM
rc.firewall vs iptables dunmarie Linux - Security 2 10-09-2003 02:00 PM
IPTables Firewall bfloeagle Linux - Security 6 06-19-2001 02:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration