LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-21-2013, 03:43 PM   #1
hearthstone
Member
 
Registered: Dec 2005
Distribution: Debian Stable
Posts: 109

Rep: Reputation: 4
Help configuring apf needed.


I did Internet search--a bit too abstruse for me ...
I like apf better than firestarter that I had before, because now all ports are "stealth" according to www.grc.com; all but port 22 that is open now.
Also - I can no longer use gftp, mutt, and some websites (including playing some Internet radio) while apf is enabled.
I run Debian stable machine.
Thanks, Hearthstone.
 
Old 01-22-2013, 08:27 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by hearthstone View Post
I like apf better than firestarter that I had before, because now all ports are "stealth"
OMG!!! One or more ports on this system are operating in FULL STEALTH MODE! "Stealth" was a craze of the past millennium ;-p


Quote:
Originally Posted by hearthstone View Post
I can no longer use gftp, mutt, and some websites (including playing some Internet radio) while apf is enabled.
While desktop applications like Firestarter have their purpose working with Netfilter, simply put, requires understanding of iptables rules (see the "Frozentux" tutorial: http://www.frozentux.net/documents/iptables-tutorial/). Using APF is a choice you make. It does not and should not give you the idea that using an application that's promoted with marketoid language and running a gazillion scripts somehow no longer requires you to understand iptables basics. On top of that if you use APF then you should consult the documentation it comes with first.

If you want to see what your current rule set looks like start by saving it with say
[code]iptables-save > /tmp/iptables.txt[code]and then reading it with your favorite text editor or try
Code:
less /tmp/iptables.txt
and maybe attach "/tmp/iptables.txt" to your next reply.
 
Old 01-22-2013, 02:12 PM   #3
hearthstone
Member
 
Registered: Dec 2005
Distribution: Debian Stable
Posts: 109

Original Poster
Rep: Reputation: 4
Strangest thing happened--I reinstalled apf-firewall, and lo, behold: as far as I can notice, I can now connect to all my Internet radio stations, mutt works, gftp works, ...

The reason that I do not learn about iptables and such is that I just want to *use* my computers--if apf takes care of iptables for me, the better!

The reason I use Linux is that some years back I was unhappy with Windows (and still am) and Linux was the alternative. At first I liked learning about Linux, but as I am getting older, the less I sit in front of the thing, the more I like it; hence if apf does the job, I am happy.

All is well now (for the time being), only the port 22 is open; But I will do some Internet search and find a way how to close it, eventually.

Btw--what's wrong with ports being "stealth"?

Thanks, Hearthstone.
 
Old 01-22-2013, 02:46 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by hearthstone View Post
I reinstalled apf-firewall,
The reflex to remove and re-install software to make things work often points to 0) the idea that practices learned using another OS are similar and should translate to similar actions when using Linux, or 1) the inability to diagnose a problem properly or 2) an unwillingness to do things "the Linux way". The practice is very rarely necessary.


Quote:
Originally Posted by hearthstone View Post
if apf does the job, I am happy.
If "happy" is an objective criterion to rate ones machines security posture with, sure.


Quote:
Originally Posted by hearthstone View Post
All is well now (for the time being), only the port 22 is open; But I will do some Internet search and find a way how to close it, eventually.
Just shut down the SSH daemon.


Quote:
Originally Posted by hearthstone View Post
Btw--what's wrong with ports being "stealth"?
While "stealth" sounds nice it just means not responding to ICMP and traceroute requests. It has nothing to do with security: it only obscures a system. Said differently: time spent tackling real security issues or concerns is time well-invested.
 
Old 01-23-2013, 06:43 AM   #5
hearthstone
Member
 
Registered: Dec 2005
Distribution: Debian Stable
Posts: 109

Original Poster
Rep: Reputation: 4
The reason that I reinstalled apf-firewall is that with that I removed all my previous configurations, and, in my view, starting "from the scratch" is, at times, most expedient way to get things done.

I removed openssh-server and all is well--the port 22 is closed according to grc.com.
sshd is/was not installed on my machine.

Thank you, Hearthstone.
 
  


Reply

Tags
apf



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Help needed in configuring puppet. pinga123 Linux - Newbie 6 07-20-2011 06:41 AM
help needed for configuring RAS athulv Linux - General 3 08-27-2009 09:16 AM
having problems viewing webpages after configuring firewall wtih APF. tuxmaster Linux - Security 2 06-28-2005 03:49 AM
iptables + apf help is needed. [gotLan]-MarK Linux - Security 3 10-26-2004 01:05 AM
Help needed configuring lilo unicef2k Linux - General 3 07-22-2004 11:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 07:10 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration