LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-29-2004, 10:25 AM   #1
Biased turkey
Member
 
Registered: Jan 2002
Location: Canada
Distribution: redhat7.2
Posts: 169

Rep: Reputation: 30
Safest: Firestarter or Fedora firewall ?


Is the default firewall that comes with the Fedora distro safe enough on my Fedora firewall-router box , or is it better to run a dedicated application like Firestarter ?
The only other service I run on my firewall is the cups server for my /dev/lp0 printer connected to it.
tia
 
Old 08-29-2004, 01:18 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Firestarter is simply a Graphical interface for configuring iptables (the standard linux firewall), so it's really the same thing. Iptables is argueably one of the more robust and effective firewalls available. However, I'd recommend doing some research on how to actually configure your firewall first.
 
Old 08-29-2004, 05:12 PM   #3
Biased turkey
Member
 
Registered: Jan 2002
Location: Canada
Distribution: redhat7.2
Posts: 169

Original Poster
Rep: Reputation: 30
I understand that both applications are based on iptables, but Firestarter has more options, like ICMP filtering and NAT enabling that are not present on what I call the "default firewall " ( KDE->system settings->Security level )
So, is one easier to crack than the other ?
Is there any Linux firewall applications rating ?
After reading the Redhat v9.0 documentation chapter about iptables ( imho one of the best short articles on the subject ) I didn't feel like rolling my own rules.
Thanks for the info but I was expecting a reply like: A is better than B, or both are crap use C instead
 
Old 08-29-2004, 06:11 PM   #4
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
If Fedora still uses lokkit, than by all means use a better front-end (Firestarter, Guarddog, etc). lokkit is the worst firewall I've ever seen, for any OS--ever.
 
Old 08-29-2004, 09:13 PM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I'm not really a big fan of lookit either. But if you're going to use something configurable like guarddog/firestarter, just make sure that do some port scanning/ pen-testing after setting it up.
 
Old 08-30-2004, 01:05 AM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Also, guarddog is designed more as a strict packet filtering firewall, so if you need any routing capabilities (NAT/Masquerading/etc), you'll need to install it's companion app called guidedog as well.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Need to understand Firestarter/firewall flashl Linux - Security 6 03-02-2005 06:30 AM
no firewall alerts - firestarter lumbrjackedpcj Linux - Security 3 01-21-2005 10:29 PM
Safest way to setup my Firewall, E-mail & Web Server matthew.collins Linux - Security 3 06-17-2004 05:38 PM
firestarter firewall thelenko Linux - Software 8 05-30-2004 03:01 AM
help with firestarter firewall luap Linux - Networking 1 03-15-2003 11:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration