LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-21-2006, 12:36 PM   #1
Slack11
LQ Newbie
 
Registered: Apr 2006
Distribution: Slackware-current-2.6.15.7
Posts: 22

Rep: Reputation: 15
linux firewall that does not allow any services


Hi guys,

I was using a script from www.projectfiles.com/firewall that should be doing the job fine.

Now I've upgrdadded my kernel and it doesn't work after I try to reinstall it. It does not even let me access the internet.

I'm wandering though as if I scan my system with www.grc.com -the well know ShieldsUp it says ALL PORTS are in STEALTH MODE which is perfect,but when I scan my system with let's say nmap it says that some ports are opened and one of these is SSH. Now I am behind a rather "advanced" router I believe,but it still (in all cases scanned with nmap or other scanner reports SSH open,in addition the install script is asking me to un-check SSH) I'm no longer using that script.



What would be your comments on the above?
Is my Reasoning correct?



I really need a firewall script that will NOT PROVIDE ANY SERVICES APART FROM LETTING ME TO ACCESS THE INTERNET.

What would you recommend that should work on my kernel(2.6.15.7 on Slackware10.2)

Many Thanks.

P.S. I feel that in each case I should have my own firewall on my linux,but what are your opinions on that as well.

Last edited by Slack11; 05-21-2006 at 12:38 PM.
 
Old 05-21-2006, 12:47 PM   #2
crash88
Member
 
Registered: May 2006
Posts: 39

Rep: Reputation: 15
Just a stab, but maybe ssh is bound to just one of your NICs. That is to say if you're running a multi-homed host, which most firewalls are. Is sshd starting up when you boot? Check dmesg. When you run nmap, I'd specifically type in the outside address to see what turns up.
 
Old 05-21-2006, 12:55 PM   #3
Slack11
LQ Newbie
 
Registered: Apr 2006
Distribution: Slackware-current-2.6.15.7
Posts: 22

Original Poster
Rep: Reputation: 15
I have 1 lan card, it's laptop in my dorm I don't think that there are multiple/virtual hosts on it.

Yes OPENSSH is starting at boot,

Yes I've always tried scanning with whatever scanner or website to the external IP address and again ALL sites reports ALL ports in STEALTH ,while the scanner apps reports some ports as OPEN including SSH

Last edited by Slack11; 05-21-2006 at 12:57 PM.
 
Old 05-21-2006, 01:18 PM   #4
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
You have router between the machine and the internet. All outside scanning sites will only scan the routers outside port. Now when using nmap and use the loopback interface of 127.0.0.1 then it will more than likely show open ports. Now if you scan the machine with the assigned IP on eth0 then it will give you more of open closed status. Best way is to use another machine in the lan to scan the machine with.

Brian1
 
Old 05-21-2006, 01:59 PM   #5
Slack11
LQ Newbie
 
Registered: Apr 2006
Distribution: Slackware-current-2.6.15.7
Posts: 22

Original Poster
Rep: Reputation: 15
that's what I thought in a very similar way.

Would you reccommend some firewall script that will run on my kernel 2.6.15.7?

Thanks.
 
Old 05-21-2006, 02:13 PM   #6
Slack11
LQ Newbie
 
Registered: Apr 2006
Distribution: Slackware-current-2.6.15.7
Posts: 22

Original Poster
Rep: Reputation: 15
Basically what I'm after is a solution to the problem - a firewall,packet filtering or smth like that,

to run on my kernel 2.6.15.7

to let ME do whatever I want on the Internet

to DENY ALL OTHERS access to my laptop

Now I hear you all saying there are thousands of firewall scripts if you do google (Yes indeed there are)


Hence why I'm asking for a Reccommendation (based from your experience or whatever else you might think of)

which one to choose,

which one will be the best in terms of catering for my requirements.

Thanks.

Last edited by Slack11; 05-21-2006 at 02:14 PM.
 
Old 05-21-2006, 04:42 PM   #7
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
Check out this link. It ask you question about your system and builds the firewall to suite your needs. I use this sometime to get started and tweak from there.
http://easyfwgen.morizot.net/gen/

Brian1
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
BSD Firewall vs Linux Firewall ? rootlinux Linux - Security 5 08-29-2007 07:38 AM
SUSe Firewall won't remove services racc11 Linux - Networking 4 01-17-2006 01:59 PM
linux services rparker8408 Linux - Newbie 4 02-23-2005 07:44 AM
Linux Services Ameii83 Linux - Software 7 12-24-2004 03:12 AM
TightVNC Ver terminal Services.. also looking for terminal Services for linux 2782d4 Linux - Security 3 05-20-2004 02:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration