LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-28-2002, 08:33 AM   #1
StrangeGirl
LQ Newbie
 
Registered: Oct 2002
Distribution: SuSe 8.0
Posts: 3

Rep: Reputation: 0
SuSe and Firestarter.


Hi

I've just run my newly installed Linux system through a variety of on-line security scans and probes from a number of different organizations, and while some results came back looking quite favourable, others were downright disturbing.

As an extremely new user, who's still plodding through the man pages and how-to's, I lack both the experience and confidence to use IP tables as a means of stealthing my ports. Does anyone here have any experience of using programmes like Firestarter on the SuSe distribution? Are there any problems caused by the SuSe firewall? I'm running SuSe 8.0 Professional on a machine that's being used as a stand alone workstation, and have Gnome fully installed (although I'm getting to grips with KDE first.)

Any assistance you could provide would be great :-)
 
Old 10-28-2002, 08:41 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well anything you would call a "firewall" under linux is probably a front end for iptables, which is in turn a wrapper for the kernels netfilter. when you load firestart it will empty any currently set up rules, so even if you do have some suse firewall gubbins in there somewhere it is unlikely to affect anything, as it should be removed by firestarter. turn it off as much as possibel anyway though
 
Old 10-28-2002, 01:25 PM   #3
nonamenobody
Member
 
Registered: Oct 2002
Posts: 138

Rep: Reputation: 22
I have found the that setting up a firewall using YaST2 is pretty good.
 
Old 10-29-2002, 05:56 AM   #4
mace
Member
 
Registered: Apr 2002
Distribution: redhat7, 7.1, 7.2, 8.0, mandrake, debian2.2, 3, suse
Posts: 176

Rep: Reputation: 30
my wife uses suse 8 and like nonamenobody said you might want to check out the firewall in yast2
 
Old 10-29-2002, 05:57 AM   #5
StrangeGirl
LQ Newbie
 
Registered: Oct 2002
Distribution: SuSe 8.0
Posts: 3

Original Poster
Rep: Reputation: 0
Re: SuSe and Firestarter

The scans were being run to test a Yast 2 configured firewall. Like you said, it's not bad by any means, although there were a couple of areas I found unsettling. Basically, I'm just looking for a nice friendly GUI to help with refinements and modifications until I've gained enough experience to do it myself.

Many thanks for the replies, all of you. It's much appreciated

Last edited by StrangeGirl; 10-29-2002 at 05:58 AM.
 
Old 10-29-2002, 09:44 AM   #6
nonamenobody
Member
 
Registered: Oct 2002
Posts: 138

Rep: Reputation: 22
If you want more functionality out of SuSEfirewall2 than is provide by the four simple set screens it may be worth taking a look at :
/etc/sysconfig/SuSEfirewall2
/etc/sysconfig/scripts/SuSEfirewall2-custom

These files allow you to set more advanced options, which YaST2 leaves out (to make things simpler). Obviously you can create your own iptables rules, but SuSE done a lot of work creating a very logical structure, to which you can bolt extra bits on, to meet your requirements.
 
Old 11-01-2002, 09:56 AM   #7
StrangeGirl
LQ Newbie
 
Registered: Oct 2002
Distribution: SuSe 8.0
Posts: 3

Original Poster
Rep: Reputation: 0
Thanks once again Nonamenobody! Sorry I couldn't reply to the post earlier - I've had the flu. *looks pale and congested*

Incidentally, on the subject of SuSE and security, according to this report http://www.egovos.org/pdf/dodfoss.pdf the Bastille hardening system is to be added to SuSE, Debian and TurboLinux either late this year, or early next year. The report is mentioned in this http://slashdot.org/articles/02/10/2....shtml?tid=117 Slashdot article. You're probably all aware of it anyway, but I thought I'd pass the info on
 
Old 11-02-2002, 09:23 AM   #8
merlinxx
Member
 
Registered: Dec 2001
Location: upstate, NY, USA
Distribution: PCLinuxOS the best
Posts: 30

Rep: Reputation: 15
SUSE & firewalls

I'm running SuSe 7.3.
I initially set up the suse fire wall with yast and am using guarddog now.

If you test your security at www.grc.com you'll find that guarddog seems to work better than the basic setup suse gives you.

With the suse firewall my ports all show up as closed but with guarddog they're stealthed.

Just M.H.O.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Open SuSE 10 + Firestarter Ace2005 SUSE / openSUSE 6 10-13-2005 05:04 PM
Firestarter problem on SuSE 9.0 Quintero Linux - Security 13 04-01-2005 02:18 AM
Firestarter for SuSE 9.0? Quintero Linux - Software 1 03-11-2005 08:33 PM
Firestarter?? BajaNick Linux - General 1 09-16-2003 07:08 AM
Firestarter tied2 Linux - General 2 07-16-2002 09:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration