LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 08-10-2005, 09:04 AM   #1
MasterOfTheWind
Member
 
Registered: Jul 2004
Distribution: Arch, Debian sid, Kubuntu, Slackware 11
Posts: 324

Rep: Reputation: 30
best linux firewall?


What do you think guys, what is the best firewall for linux?
 
Old 08-10-2005, 09:11 AM   #2
dukeinlondon
Member
 
Registered: May 2003
Location: London
Distribution: kubuntu 8.10
Posts: 593
Blog Entries: 1

Rep: Reputation: 30
My option is to use my router's firewall personnally.


I had no problem whatsoever with it in 3 years and it's rather cheap..

In the past, I used guarddog. Nice interface but a bit tedious. It might have changed for the best since then though.

Last edited by dukeinlondon; 08-10-2005 at 09:12 AM.
 
Old 08-10-2005, 09:22 AM   #3
xxx_anuj_xxx
Member
 
Registered: Jun 2004
Location: Bharat
Distribution: RedHat, Debian, FreeBSD, Fedora, Centos
Posts: 114

Rep: Reputation: 16
I tried shorewall . It is cool!
http://shorewall.net/
 
Old 08-10-2005, 09:42 AM   #4
ralvez
Member
 
Registered: Oct 2003
Location: Canada
Distribution: ArchLinux && Slackware 10.1
Posts: 298

Rep: Reputation: 30
I have experienced, over time, different possibilities. I've used IPTABLES (written my own tables) in order to learn.
Currently, for my personal computer I use Firestarter, which I consider a very reliable and easy to use firewall.
For my router I use Smoothwall. It is small (under 250MB) has a nice web interface for the administrator and I find it friendly and reliable.

Hope this helps.

Rick
 
Old 08-10-2005, 10:11 AM   #5
SlackerLX
Senior Member
 
Registered: Dec 2004
Location: Herzliyya, Israel
Distribution: SuSE 10.1; Testing Distros
Posts: 1,832

Rep: Reputation: 47
Some of our members reported overload of shorewall when traffic is hit by virus for M$ machines. IPTABLES is easy enough and without implementations and "improvements"
 
Old 08-10-2005, 02:11 PM   #6
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,671
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
As far as I can see (and I use it), Shorewall is simply an iptables-rule generator. It has no active components. I believe that the stories of an "overload" must be mistaken.

Of course, the processing of iptables rules does require a certain amount of CPU power per-packet. Here, a hardware firewall on the front-end, e.g. within the router leading in from the DSL line or cable-modem, can be very useful. It will strip out most of the unwanted traffic, leaving Linux to deal only with a small percentage.
 
Old 08-10-2005, 02:28 PM   #7
zWaR
Member
 
Registered: Dec 2003
Distribution: Slackware, Alpine Linux, Ubuntu, Debian
Posts: 219

Rep: Reputation: 35
Learn iptables and write the rules by yourself!! Ethereal is a great help! Besides it is good to learn something about the firewall theory and different firewall "architectures" in order to write a good set of iptables rules: http://www.unix.org.ua/orelly/networ...fire/index.htm
 
Old 08-10-2005, 02:35 PM   #8
linux=future
Member
 
Registered: Apr 2005
Distribution: Debian
Posts: 154

Rep: Reputation: 30
iptables is extremely powerful. It is in the kernel itself, instead of being a program running on top of the kernel. This makes it hard to hack (typically). The downside is that you need to learn how to manually configure it if you want it to be perfect.
 
Old 08-10-2005, 02:50 PM   #9
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
I believe there is only ONE firewall in linux, which is "iptables" (in fact it's part of the kernel), it replaces the old "ipchains" now.

In case you are asking about a front-end (GUI) to it, then there is plenty, but they are all bad at my opinion. Writign a firwall script is just a bad thing to do trought a GUI, you will always be limited at some time and drive into problem. You better just write it yourself by hand. It's not hard at all.
 
Old 08-10-2005, 04:09 PM   #10
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Rep: Reputation: 45
if you are wanting a dedicated firewall, router, proxy, NAT box, then i sujest looking into www.ipcop.org

this is a little 50M self installing CD that can handle up to 4 NICs. one for RED (connected to your ISP), GREEN (LAN safe side), BLUE (WiFi, different subnet then GREEN) and ORANGE as your DMZ again a different subnet.

has a nice little https: web interface and right out of the box is very secure, you can lock it down tighter as it does run iptables and there are plenty of pre-configured add-ons for blocking things.

this also does VPNs and much much more. check them out.
 
Old 08-11-2005, 12:42 PM   #11
MasterOfTheWind
Member
 
Registered: Jul 2004
Distribution: Arch, Debian sid, Kubuntu, Slackware 11
Posts: 324

Original Poster
Rep: Reputation: 30
All right, thanks everyone I think I'll stick to IPTables for now, as many of you suggested....
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
BSD Firewall vs Linux Firewall ? rootlinux Linux - Security 5 08-29-2007 07:38 AM
how to m$ win client+firewall to linux sshd and use linux to access the M$ computer c_mitulescu Linux - Networking 7 05-14-2004 12:56 PM
Linux As A Firewall 311Sam Linux - Security 8 01-04-2004 01:46 PM
linux firewall nuhn123 Linux - Newbie 3 09-07-2003 11:47 PM
Linux Firewall preguin1 Linux - Security 7 04-05-2001 04:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 01:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration