LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-09-2007, 08:17 AM   #1
jonfa
Member
 
Registered: Mar 2001
Location: FL
Posts: 257

Rep: Reputation: 30
manually adding rules w/ firestarter installed


Hi All,

I have firestarter installed on my Centos 4.4 box and it works well. I want to add more specific rules manually from the command line and not mess up my firestarter rule set. Is this a good idea?

I've noticed that firestarter stores its entries in the /etc/firestarter directory and if I add manual entries they are stored in /etc/sysconfig/.

Is it possible to use both firestarter and manual entires together?

Thanks.
 
Old 03-11-2007, 12:34 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Is it possible to use both firestarter and manual entires together?
Short answer: yes and no ;-p

Long answer: your box comes with it's own iptables package. It's firewalling rules live in /etc/sysconfig/iptables. Using "iptables", these rules are loaded into kernel land. Firestarter is (amongst other things) a tool to help build rules. Using "iptables", these rules are loaded as well. I don't know if they are added to or override the default CentOS rules but it would be easy to find out by looking at the chain names as the default RHEL package uses distrinct naming. Furthermore, if you manually add rules *and* configure iptables to save rules on "service" reload or reboot it will only affect /etc/sysconfig/iptables. This means Firestarter no longer has access to all rules unless it uses something like "/sbin/iptables -n --line-numbers -t $TABLENAME -L $CHAINNAME" which I doubt. You can view this as a positive argument for mucking around manually with rulesets because you always have "untainted" Firestarter rules to fall back on (provided the service loads on boot *and* overrides the default ruleset) or a negative argument if you need to rely on one central tool to administer the firewall. As with most things GNU/Linux the choice is yours.

* Of course I could be horribly wrong. I vaguely remember playing with Firestarter a few times but that was ages ago.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
KDE Config files - manually adding key shortcuts jreich383 Linux - General 2 09-14-2006 11:01 AM
Just installed my first program manually, how do I open it? (Ubuntu) xLunatiK Linux - Newbie 4 01-31-2006 12:35 AM
Using Firestarter ... Can I Add/Drop rules from a terminal prompt? rickh Linux - Security 1 06-15-2005 03:21 AM
Adding spamassassin rules when filtering with mimedefang? justanothergeek Linux - Software 0 02-16-2005 10:18 PM
Permanently Adding iptable rules GUIPenguin Linux - Networking 2 10-12-2004 11:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration