LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-10-2004, 11:08 PM   #1
bzsleeping
LQ Newbie
 
Registered: Jun 2003
Location: at my desk.. sleeping
Distribution: Red Hat 9.0 with latest kernel.. i think :p
Posts: 27

Rep: Reputation: 15
need more info on firewall configuration


hai all..

i'm quite new with linux.. but being the only one in my office that understand linux and using it, i have been chosen to install a firewall for my co.

now.. i know nothing about firewall.. except that they block u from accessing some juicy sites.. hhehehe.. but i want to try it and learn something new.

i google the internet about firewall (and here too) and to tell u the truth.. it made me even more confused.. i'm quite sure my co requirements is not that complicated and IMO it must be quite easy..

my co asked me to install ipcop. now i'm familiar with iptables and a few squid acls.. is ipcop using the same thing? whats bugging me.. during the installation my painintheass boss will be there during the installation + configuration. i dont want to look lost coz if i do.. he'll gonna raise some hell.

i've seen a working ipcop at my friend's office.. looks intimidating.. anyone know where to learn more about ipcop.. i meant a real world working example or walkthrough coz i dont want to scew up. i think installing it is not a problem for me just the configuration part.
 
Old 06-11-2004, 12:22 AM   #2
LoK
Member
 
Registered: May 2004
Location: Detroit MI
Distribution: RHE & FC
Posts: 31

Rep: Reputation: 15
Good luck man... I wouldn't tolerate my boss looking over my solder. No one can work like that and this isn't something that is going to take 5 minutes.

You will spend time installing, reading references, initial setup, reading more references, configuration, yeap.. more references, testing, tweaking, read why xxx isn't working, tweaking....

That is not the time for "why is it doing that?", "Ok tell me what you just did so I know how to do it", etc...

If I were you, I would ask my boss to leave me to it and once I had it completed I would provide a process on installation, configuration, and then a walk through. For the walk through hook a client pc up to it so he can see how it interacts, logs, etc.

Just be sure to take lots of notes Also, you definately should be installing it and testing it on your own if you plan on going through with this.

Hearing about someone with a boss like that makes me angry. Frankly, I wouldn't want to be in your shoes when/if it crashes. Running something like a firewall in a production environment with little or no real world experience is a dangerous endeavor. When it goes down you won't have access to the net, nor will you have a tech support number to call for help.

If the company is of any size I would suggest you spend some money on a product with support directly from the maker, such as Astaro. At the very least find a company near you that supports IPCop and contact them about their rates.

When the whole place goes down (it's only a matter of time) you will thank god you did
 
Old 06-11-2004, 01:05 AM   #3
bzsleeping
LQ Newbie
 
Registered: Jun 2003
Location: at my desk.. sleeping
Distribution: Red Hat 9.0 with latest kernel.. i think :p
Posts: 27

Original Poster
Rep: Reputation: 15
yea.. man. it sucks big time. but unfortunately, unless something bad happen to him *evil grin*, its unavoidable. *sigh*.

i guess i can go through the whole process of configuring quite easily.. its just that i need the cushion if it wont work. espcially when i lock myself out from the internet. *gulp*
 
Old 06-11-2004, 10:42 AM   #4
LoK
Member
 
Registered: May 2004
Location: Detroit MI
Distribution: RHE & FC
Posts: 31

Rep: Reputation: 15
Well, and easy way to be safe (cheaper anyways) is to get it all up and running and then use a product like Altiris to image the drive, create a restore disk, and cp the image to a server internally.

Then if anything goes wrong with it you will always be able to start fresh again without reinstall/configuration. If you decide to do something like that (be it altiris, ghost, etc) just be sure to create a new image ANY TIME you make a change
 
Old 06-11-2004, 02:16 PM   #5
Garak
LQ Newbie
 
Registered: Feb 2003
Location: Seattle, WA
Posts: 16

Rep: Reputation: 1
homeLANsecurity

If you're looking around for a good firewall, I'd suggest taking a look
at homeLANsecurity 1.4.0.
I run this firewall myself and it not only has all the features I want,
but is incredibly easy to configure.

Just thought I'd put in my two cents about that part of it. I have no
idea about ipcop. I too would have a hard time putting up with a
boss like yours. Amazing what we'll do for a paycheck huh?

Good luck!
 
Old 06-24-2004, 07:34 PM   #6
bzsleeping
LQ Newbie
 
Registered: Jun 2003
Location: at my desk.. sleeping
Distribution: Red Hat 9.0 with latest kernel.. i think :p
Posts: 27

Original Poster
Rep: Reputation: 15
update..

well.. well.. well.. the installation went smoothly. all under 30 mins. ipcop works great! updating the patches was easy. setting the rule was simple. ipcop had been up and running for two weeks with no problem. i'm very impressed with it. and so does my boss. hehehehe...

maybe now is a good time to discuss with him about a pay raise eh?
 
Old 06-27-2004, 07:07 PM   #7
fotoguy
Senior Member
 
Registered: Mar 2003
Location: Brisbane Queensland Australia
Distribution: Custom Debian Live ISO's
Posts: 1,291

Rep: Reputation: 62
I use Ipcop at home myself and it runs perfectly, just remember to check your firewall and IDS log files regularly
 
Old 06-28-2004, 12:15 AM   #8
Mr-TY
LQ Newbie
 
Registered: Jun 2003
Location: Australia
Distribution: RedHat
Posts: 4

Rep: Reputation: 0
I like to use iptables, an important thing to know is your highs and low ports.
A server and a client machine send and receive though there ports a little differently.

i'll post up an example later,
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall configuration EvilAngel Linux - Networking 3 02-05-2005 07:23 AM
Firewall configuration pedrog Linux - Security 4 02-03-2005 06:04 AM
firewall configuration Santas Mandriva 7 12-19-2003 10:06 AM
NOOB: Firewall how do I configure it to block all incoming info? PionexUser Linux - Security 1 11-19-2003 10:39 PM
info on syslog configuration markus1982 Linux - Software 1 05-26-2003 11:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration