LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-13-2003, 11:00 PM   #1
foreplay
LQ Newbie
 
Registered: Jun 2003
Distribution: Red Hat 8.1
Posts: 8

Rep: Reputation: 0
Red face Linux Firewall


I have a RedHat Linux 8.1 running as a server/router with a DSL connection with Win98 as clients... I have some applications on each workstations that require me to turn off the Linux Firewall (e.g. Kazaa, WebCam of Yahoo! Messenger). I've tries almost all of the suggestions within the posts i can find regarding Firewalls. Nothing seems to solve my problem, my Kazaa still can't connect and my Y!M videoCam feature sill won't work... I'll appreciate any help anyone can give me... thanks...
 
Old 06-14-2003, 06:16 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I have some applications on each workstations that require me to turn off the Linux Firewall (e.g. Kazaa, WebCam of Yahoo! Messenger).
Don't, adjusting the rules shouldn't be that hard.

I've tries almost all of the suggestions within the posts i can find regarding Firewalls.
Tell us which ones. Talking *about* them ain't gonna solve it, right?

Here's two things I would like you to do.
I. Add, and make sure every rule of in and outbound traffic on the fw is logged. This is the start of any basic troubleshooting, because reading back the logs you know what kind of traffic goes out, where it goes and to which ports. Reading the DROP lines will get you a feel for what's missing soon enough. Try each app a few times and in between try to get a grip on the patterns (TCP/UDP, IP or ranges, ports). Once you have them, try to build rules for them.

II. Google around for the ports P2P apps and IM's use. Correlate this with the rules you made as a result of the previous item. Adjust your rules and try them out. Again note DROP rules and adjust your rules.

Finally post your fw script and the IM/P2P rules you tried here, then we got a base to go over it. Other LQ members may see this as too complicated and may offer you the rules directly, but IMO this is the best approach to learn it and apply your knowledge again when needed in another situation, keep that in mind.

Last edited by unSpawn; 06-14-2003 at 06:18 AM.
 
Old 06-15-2003, 09:42 PM   #3
foreplay
LQ Newbie
 
Registered: Jun 2003
Distribution: Red Hat 8.1
Posts: 8

Original Poster
Rep: Reputation: 0
uh, i don't know how to set rules... sorry...
 
Old 06-15-2003, 09:57 PM   #4
Zyen
LQ Newbie
 
Registered: Jun 2003
Posts: 2

Rep: Reputation: 0
Talking unSpawn...

I have been searchin for help on *nix fw for a few days now, and i must say that is the BEST advice i've found.
I just wanted to post that, with my thanks.

Zyen
 
Old 06-15-2003, 10:35 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I'm rather astounded to find someone is willing to make his first post a compliment... Anyway, thnx Zyen, it's good to get feedback.

Foreplay, did you read at least some docs on Linux firewalling? (Just checking where we should start, ok)

Last edited by unSpawn; 06-15-2003 at 10:37 PM.
 
Old 06-16-2003, 12:06 AM   #6
Zyen
LQ Newbie
 
Registered: Jun 2003
Posts: 2

Rep: Reputation: 0
unSpawn,
I call 'em like i see 'em.
anyway, with that single piece of advice, i was able to set my firewall pretty much like i wanted it.
now for the rest (like foreplay is talking about with yahoo!, etc).

foreplay, good luck. if i find out any advice when i get mine working that i feel should be passed on, i'll let ya know.

Zyen
 
Old 06-16-2003, 10:43 PM   #7
foreplay
LQ Newbie
 
Registered: Jun 2003
Distribution: Red Hat 8.1
Posts: 8

Original Poster
Rep: Reputation: 0
re : Foreplay, did you read at least some docs on Linux firewalling? (Just checking where we should start, ok)

nope... sorry, couldn't find any docs that could be of help...
 
Old 06-17-2003, 01:03 AM   #8
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
Newbie always tought a firewall gonna drop apps like Kazaa or ICQ because stupid winbloze firewall (if we can call it like this) are too bad and so drop this trafic.
Linux firewall aren't dumb (especially because YOU have to code your own rules) they will not drop anything you don't want too...

have you TRIED the linux firewall before complaining?
 
Old 06-17-2003, 02:04 AM   #9
foreplay
LQ Newbie
 
Registered: Jun 2003
Distribution: Red Hat 8.1
Posts: 8

Original Poster
Rep: Reputation: 0
uh, i am running a linux firewall...
 
Old 06-17-2003, 07:15 AM   #10
Read_Icculus
Member
 
Registered: Oct 2002
Distribution: MDK 9.2, Debian
Posts: 74

Rep: Reputation: 16
Running Kazaa without a firewall is almost like asking to be hacked. Everyone you are downloading from/uploading to knows your IP addy. I guess the question now is what firewall? The default one with RH? I'm not familiar with how it works, but here is a page that tells you what you'll need to open -

Kazaa - http://www.pcflank.com/fw_rules_for_app.htm?appid=101

Messenger - http://www.pcflank.com/fw_rules_for_app.htm?appid=137

So if you know how to futz with your ports you should be all good.
 
Old 06-17-2003, 08:24 AM   #11
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Thanks, Read_Icculus! Excellent!
I totally forgot about the Pcflank ports database.
I'll add it to the "FAQ: Security references" thread.
 
Old 06-17-2003, 11:05 PM   #12
foreplay
LQ Newbie
 
Registered: Jun 2003
Distribution: Red Hat 8.1
Posts: 8

Original Poster
Rep: Reputation: 0
how do i set rules??? can anyone post in a step by step process if noone minds... tnx...
 
Old 06-19-2003, 06:30 AM   #13
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Well... how did you set them up when you set up the RH server/router in the first place? Using a GUI?
 
Old 06-19-2003, 01:30 PM   #14
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
you have a firewall but never set rules?
strange...
 
Old 06-19-2003, 01:42 PM   #15
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Half, don't post useless comments. Help out or bail out.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
BSD Firewall vs Linux Firewall ? rootlinux Linux - Security 5 08-29-2007 07:38 AM
how to m$ win client+firewall to linux sshd and use linux to access the M$ computer c_mitulescu Linux - Networking 7 05-14-2004 12:56 PM
Linux As a Firewall shaundyc Linux - Security 8 05-07-2004 11:56 AM
A Firewall for linux marsques Linux - Security 7 01-08-2004 12:41 PM
Linux Firewall preguin1 Linux - Security 7 04-05-2001 04:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration