LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-08-2001, 07:31 AM   #1
Artman
LQ Newbie
 
Registered: Nov 2001
Posts: 3

Rep: Reputation: 0
Win XP gateway security strategy


Hi,
My home network consists of 2 computers: a Linux and a Win XP. Due to hardware restrictions, the Win XP will act as an internet gateway (dial-up PPP account). I'm currently running Norton Personal Firewall on this box.

My question concerns the Linux box: do I need to install a firewall here eventhough I already have one in XP? Should I be worried about closing off ports for telnet, ftp, etc? I'm the only user in this little network.
Thanks,
Art
 
Old 11-09-2001, 10:18 PM   #2
tarballedtux
Member
 
Registered: Aug 2001
Location: Off the coast of Madadascar
Posts: 498

Rep: Reputation: 30
Hmmm...

Although I'm completely against using Micro$oft as a security product, you should limit connections, including:


telnet (if you don't use it)
ftp (if you don't use it)
I personally take all ICMP packets out, that stops alot of funky script kiddying.
if you get deep into the ipcains jungle, consider not allowing SYN flagged packets on the inbound at all unless you explicitly allow want them.


If tyhis helps (YEAH!)
If not post again for a refined reply
 
Old 11-10-2001, 02:04 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
uhm, that's understandable, about the ICMP part, but It's gonna break stuff.
Try allowing all types outbound, but inbound only type's 0,3,4,5,9,12,14.
 
Old 11-10-2001, 10:52 AM   #4
[BHBS]=TK
Member
 
Registered: Aug 2001
Location: Salt Lake City, UT
Distribution: REDHAT 7.1
Posts: 32

Rep: Reputation: 15
The answer to your question depends on what you plan to be doing. Are you going to run the XP box or the Linux box with any server capabilites?
If you are going to run them as workstations, just disable ICMP requests and you should be relatively invisible to the rest of the world.
If you are going to run services , then which ones?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall Security / Gateway Routing colabus Linux - Networking 1 09-13-2005 11:15 PM
Firewall Security / Gateway Routing colabus Linux - Security 3 09-09-2005 06:40 PM
Interesting Security Strategy junkken Linux - Security 3 02-03-2005 07:39 AM
Odd problem: Gateway unreachable after certain amount of time (Win XP Gateway) SocialEngineer Linux - Networking 2 08-13-2004 12:54 AM
gateway access security? andzerger Linux - Networking 4 02-20-2004 01:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration