LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-03-2003, 04:10 PM   #1
christophe.dr
LQ Newbie
 
Registered: Aug 2003
Location: Paris
Distribution: mandrake 9.1
Posts: 26

Rep: Reputation: 15
Snort, prelude, fwbuilder, bastille or iptables ?


Hi !
Short newbie question :
Is it better to have snort , prelude, fwbuilder, bastille or iptables for a personal firewall ?
And is it a good thing to have them running together ?
Merci.
Spassiba.
Thanks.
Efraristo.
Danke.
Grazie.
Gidos
Gracias.
 
Old 10-03-2003, 06:27 PM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
For the last time SNORT IS NOT A FIREWALL If I had a dollar for every time I've pointed that out...

Look, firewalls are packet filters and/or proxies. They work by actively interrupting traffic. Intrusion Detection Systems (such as Snort) are mostly passive and do not block traffic as a general rule. Additionally, IDSs look at many more characteristics of traffic besides just what ports the traffic is using. Most firewalls will only look at source/destination port/ip to make their decision.

By the way, it's my understanding that Prelude is another IDS and as such, NOT A FIREWALL EITHER. I could be wrong on that one.

fwbuilder is a program which will let you create firewall rules and write them to a configuration file for several of the popular firewalls. The short list of supported firewall types is pf (OpenBSD), ipfw (FreeBSD), iptables (Linux), and PIX (Cisco Security PIX--which BTW does NOT RUN IOS despite what some ignorant people will tell you). fwbuilder is not actually a firewall, is a firewall configurator.

Last, Bastille. Well, from what I know Bastille is actually a set of lockdown scripts which change filer permissions and generally tighten your system security in an automated fashion. Mandrake Linux has it's own program to perform this function, it's called msec (Bastille will run on just about any Linux SFAIK). The last I knew, Bastille did NOT have a firewall, although it's possible that it now has iptables rules that it loads.

So you see, you're comparing apples to oranges. Snort and Prelude are IDSs, fwbuilder is just a firewall configurator (you still need something to run the firewall), Bastille is (so far as I know) only a lockdown script and not a firewall, iptables is actually a set of kernel modules that will let you install a firewall.

Firewalls that I know of: Firestarter, Guarddog, SNF (Mandrake's Single Network Firewall) and um... that's pretty much it. You can use fwbuilder to setup an iptables firewall, though. Obviously you'll only have access to SNF if you run Mandrake.
 
Old 10-04-2003, 12:02 AM   #3
jymbo
Member
 
Registered: Jan 2003
Posts: 217

Rep: Reputation: 30
I use iptables in conjunction with a very simple yet powerful iptables script called gShield.
 
Old 10-04-2003, 07:03 PM   #4
mysterio
Member
 
Registered: Sep 2003
Location: Springfield Ma.
Distribution: Mandrake 9.2,Knoppix 3.7,Slackware 10.0, FreeBSD. 5.3, OpenBSD 3.6, NetBSD 2.0, Debian
Posts: 275

Rep: Reputation: 30
I'm pretty sure (not positive) that bastille is also a firewall.
 
Old 10-07-2003, 06:11 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I'm pretty sure (not positive) that bastille is also a firewall.
Sure. And DOS too, I mean, it's not lettin ANYTHING tru :-]
 
Old 10-28-2003, 01:59 PM   #6
gfyspf
LQ Newbie
 
Registered: Jul 2003
Posts: 17

Rep: Reputation: 0
for a personal firewall I would just use iptables. Once you get the hang of writing the rules it is very easy. there are plenty of examples on line.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Using Snort with iptables,How to dimsh Linux - Security 2 09-24-2005 08:15 AM
FWBuilder + iptables + fedora -> port forwarding the_reen Linux - Security 2 09-04-2004 12:34 PM
how to generate iptables script using fwbuilder Skunk_Face Linux - Security 1 04-23-2004 10:06 PM
Which Firewall Prelude or Snort? DavidTempler Linux - Security 4 11-11-2003 01:58 PM
snort and iptables on same machine cestor Linux - Security 8 06-13-2002 03:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration