LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 12-27-2014, 10:09 AM   #1
BAcidEvil
Member
 
Registered: Dec 2003
Distribution: Slack 14.1 3.18.1
Posts: 293

Rep: Reputation: 10
DMZ and Linux


If I were to set up IPTABLES and/or Open-Close Ports specifically on my Linux Machine would it be better to set the Internal IP for the Linux to have DMZ enabled on the router?
 
Old 12-27-2014, 10:52 AM   #2
Mark Pettit
Member
 
Registered: Dec 2008
Location: Cape Town, South Africa
Distribution: Slackware 15.0
Posts: 619

Rep: Reputation: 299Reputation: 299Reputation: 299
I'm not sure how you're planning on setting this up, but my advice is to use a decent firewall that will do the work for you. Personally I recommend Shorewall.
 
Old 12-27-2014, 10:58 AM   #3
BAcidEvil
Member
 
Registered: Dec 2003
Distribution: Slack 14.1 3.18.1
Posts: 293

Original Poster
Rep: Reputation: 10
Quote:
Originally Posted by Mark Pettit View Post
I'm not sure how you're planning on setting this up, but my advice is to use a decent firewall that will do the work for you. Personally I recommend Shorewall.

Long story then;

Instead of me using Port Forward for every little port I want enabled such as http, 113, (sshd port) so on and so forth in my Router, could I not just give all access (isn't that what DMZ is or am I misunderstanding) and then do the blocking of ports on the Linux box?
 
Old 12-27-2014, 11:01 AM   #4
BAcidEvil
Member
 
Registered: Dec 2003
Distribution: Slack 14.1 3.18.1
Posts: 293

Original Poster
Rep: Reputation: 10
Quote:
Originally Posted by Mark Pettit View Post
I'm not sure how you're planning on setting this up, but my advice is to use a decent firewall that will do the work for you. Personally I recommend Shorewall.


Oh and BTW I will looking into Shorewall, thank you.
 
Old 12-27-2014, 01:08 PM   #5
Gerard Lally
Senior Member
 
Registered: Sep 2009
Location: Leinster, IE
Distribution: Slackware, NetBSD
Posts: 2,177

Rep: Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761Reputation: 1761
Quote:
Originally Posted by BAcidEvil View Post
Long story then;

Instead of me using Port Forward for every little port I want enabled such as http, 113, (sshd port) so on and so forth in my Router, could I not just give all access (isn't that what DMZ is or am I misunderstanding) and then do the blocking of ports on the Linux box?
Assuming you don't have to open more than a handful of ports, it wouldn't be too difficult just to open the ports on both router and Slackware machine. Let the router forward them to Slack and have netfilter/iptables on Slack handle the filtering. If these ports are just for your own use and not for the public you could instead set up OpenVPN on Slack and have just UDP 1194 forwarded from the router to Slack; then you would access the services (ssh, http, imap, etc.) as if they were on a LAN, with no port forwarding or filtering other than UDP 1194 for OpenVPN required.

If you have a DMZ port on your router, and you are offering web and other services to the public, you should attach your public-facing server to the DMZ. This should really be a different machine, and not your everyday Slackware workstation; leave that connected to the LAN port on your router and don't allow public connections to it, unless you want SSH or OpenVPN.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
The router with the function of DMZ ? What is DMZ? wertum Linux - Networking 3 08-10-2010 04:05 AM
DMZ - linux outbound request not going out linuxguy08 Linux - Server 1 05-23-2008 06:24 PM
To DMZ or not to DMZ. That is the question. MykeV Linux - Networking 6 10-02-2007 01:12 PM
question about iptables (DMZ machine connect to other DMZ machine 's publuic IP) wingmak Linux - Security 1 01-20-2007 04:01 PM
suse linux and dmz masalsbury Linux - Networking 1 11-04-2004 10:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 01:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration