LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-14-2005, 07:48 PM   #1
Kamikazee
Member
 
Registered: May 2005
Location: Aus
Distribution: SimplyMEPIS 3.3
Posts: 107

Rep: Reputation: 15
Shorwall .Vs. Guarddog


Im currently using the guarddog Firewall and considering installing Shorewall instead.

Is shorewall easy to configure indevidual ports? provide DHCP support?
 
Old 07-15-2005, 01:56 PM   #2
Skyline
Senior Member
 
Registered: Jun 2003
Distribution: Debian/other
Posts: 2,104

Rep: Reputation: 45
Re: Shorwall .Vs. Guarddog

Quote:
Originally posted by Kamikazee

Is shorewall easy to configure indevidual ports?
To give you an introductory idea were individual ports are explicitly specified, and as an example - you can use "syntax" like:

Code:
# /etc/shorewall/rules

ACCEPT fw net udp 53
ACCEPT fw net tcp 25,80,110,443,6667
As you can see, we're allowing outbound connections to those specified ports.

(The above code from an /etc/shorewall/rules file could be used in combination with a "drop all outbound" type of policy in an /etc/shorewall/policy file (for a basic workstation, for example)).

As ever, to get the best out of it, it's a case reading up a little on the Shorewall documentation - alternately, if Guarddog is currently sufficient for your needs then you might want to stay with that - plenty of choice though, as ever

Last edited by Skyline; 07-15-2005 at 02:15 PM.
 
Old 07-15-2005, 11:15 PM   #3
JARofHERB
Member
 
Registered: Apr 2004
Location: Pacific Northwest
Distribution: Debian unstable
Posts: 60

Rep: Reputation: 15
I use firestarter, and think that it is alot better than both guardog and shorewall, check it out man....
 
Old 08-12-2005, 11:14 AM   #4
neilcpp
Member
 
Registered: Jul 2003
Location: England
Distribution: Debian Jessie, FreeBSD 10.1 anything *nix to get my fix
Posts: 329

Rep: Reputation: Disabled
Cool

I have just started using firestarter. Took 5 minutes to download and get it installed and running. If your after ease of use I would suggest this program.
 
Old 08-12-2005, 02:33 PM   #5
Vgui
Member
 
Registered: Apr 2005
Location: Canada
Distribution: Slackware
Posts: 496

Rep: Reputation: 31
I recommend Shorewall, mainly because it just does the job with no hassle. Even if you use the default / sample configuration you are "locked down" right off the bat.
Guarddog and Firestarter do have GUIs though, but I find them more intrusive.
In the end, they all get the same job done (which is tuning your iptables).
 
Old 08-12-2005, 03:53 PM   #6
xxx_anuj_xxx
Member
 
Registered: Jun 2004
Location: Bharat
Distribution: RedHat, Debian, FreeBSD, Fedora, Centos
Posts: 114

Rep: Reputation: 16
I am agree with Vgui for recommending Shorewall
Just go the the site and read the instructions easy to configure also you can download configuration files from
Sample Configurations
Good performance.
 
Old 08-12-2005, 04:23 PM   #7
mrcheeks
Senior Member
 
Registered: Mar 2004
Location: far enough
Distribution: OS X 10.6.7
Posts: 1,690

Rep: Reputation: 52
I am using firehol but i was using shorewall which i find pretty good. As long as the firewall scripts or front-ends you intend to use, are well tested , stable and documented, i guess it is ok.
 
Old 08-15-2005, 07:25 PM   #8
adrianmak
Member
 
Registered: Dec 2002
Posts: 56

Rep: Reputation: 15
i recommend shorewall too
It is really feasible in configurate ur rules, hiding details of iptables and provide a high level user friendly concept
shorewall provided other features that firestarter nor guarddog is missed
e.g. traffic accounting, vpn, tos, etc

if people want a graphical gui, you can install webmin which included a shorewall module

of course if you want to get the full power of shorewall, you should get into the shorewall config files directly
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Guarddog and 2.6.0 powadha Slackware 2 01-09-2004 12:10 PM
guarddog and 2.6.0 ? shanenin Linux - Security 2 01-01-2004 12:30 PM
guarddog maybe? corbintechboy Slackware 0 10-06-2003 08:13 PM
Guarddog help leeach Mandriva 3 10-02-2003 04:02 PM
Guarddog Help! wonderpun Linux - General 4 08-21-2002 02:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:15 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration