Fedora Linux Support Community & Resources Center
  #1  
Old 6th July 2004, 02:26 AM
ems Offline
Registered User
 
Join Date: Apr 2004
Posts: 36
that FC2 Firewall

Hello

So how good is the FC2 firewall ?
Is it better than Firestarter ? or Guarddog ?

I went to grc.com, and what showed up was that while the majority of ports were stealth, a few were closed, but none were open.
Is that anything to worry about ?

Much thanks
ems
Reply With Quote
  #2  
Old 6th July 2004, 02:40 AM
deuch Offline
Registered User
 
Join Date: Apr 2004
Location: France
Age: 34
Posts: 340
Firestarter or guarddog are frontend for iptables the firewall in FC2.

Firestarter is easy to use and you can stealthe port that you don't use ...

Stealth is the best because it's like that this port doesn't exist ... Closed ports are ports that are visible but not accessible.

There are some HowTo and tutoriel to enable rules in iptables on the net ... try a google search

deuch
Reply With Quote
  #3  
Old 6th July 2004, 06:21 AM
Cr0n_J0b Offline
Registered User
 
Join Date: Jun 2004
Posts: 75
I use firestarter for the GUI setup...after that read an IPtables Howto for more indepth setting...

Just remember, the firewall is the same...IPtables...you set rules in a config file that is checked when matching packets...

IPTables is an EXCELLENT firewall with almost every feature you would ever need.

If you want to turn a small linux box into a dedicated firewall, I would look at smoothwall.
Reply With Quote
  #4  
Old 6th July 2004, 01:47 PM
ems Offline
Registered User
 
Join Date: Apr 2004
Posts: 36
Well I have hear that Smoothwall is a bit of a horse.

It's a pity that Guarddog is not available for FC2, altho it is for FC1 ( which makes me wonder if the FC1 version might not work in FC2 ).

The thing with Guarddog ( from my experience with it in Mandrake ) is that when you do the grc.com Shield test, it delievers a complete stealth result.
On the otherhand for some reason, the native firewall in FC2 and Firestarter both leave various as ' closed ' and the rest as ' stealthed '.

Also Guarddog is a very good piece of front-end, so maybe I've been spoilt by it.

Cheers ems
Reply With Quote
  #5  
Old 6th July 2004, 01:57 PM
flea's Avatar
flea Offline
Registered User
 
Join Date: Apr 2004
Location: raleigh, NC
Age: 31
Posts: 97
i like shorewall myself
__________________
fleabags. :cool:
gangster in training.
Reply With Quote
  #6  
Old 6th July 2004, 02:31 PM
ems Offline
Registered User
 
Join Date: Apr 2004
Posts: 36
I went and had a look at Smoothwall.
Is it really a 20 meg application ?

Sounds huge !
Gosh what does it have in it ?

or am I missing something ?

cheers ems
Reply With Quote
  #7  
Old 6th July 2004, 03:12 PM
Varkk Offline
Registered User
 
Join Date: Mar 2004
Location: New Zealand
Age: 34
Posts: 285
Smoothwall is not an application, but a standalone linux distro which is designed to only act as a firewall/router. You set it up on an old PC, plug your modem/router/whatever you connect to your ISP with and pop it in a cupboard or something. We use it at our flat to share out our ADSL connection to our PCs and laptops.
Reply With Quote
  #8  
Old 6th July 2004, 03:17 PM
Bana's Avatar
Bana Offline
Retired Community Manager
 
Join Date: Feb 2004
Location: Austin, Texas
Age: 26
Posts: 581
Yes I also use it and can attest to its usefullness. The remote web access setup is superb and it never lets me down.
__________________
http://coolhands.blogspot.com/
binarybana AT gmail.com
Reply With Quote
  #9  
Old 6th July 2004, 03:50 PM
sailor's Avatar
sailor Offline
Registered User
 
Join Date: Mar 2004
Location: San Antonio, Texas
Age: 55
Posts: 3,996
Correct me if I am wrong, but I have heard that if you are using a router (I have a Linksys befsr41) that a firewall is not necessary. I have gone to grc.com(Shields Up!) and all is good all ports stealth..etc...I have tried this wIth both WIndows and FC2 with no firewall and the same, all ports are stealth...
__________________
sailor
Fedora 16, Mac OSX Snow Leopard, Windows 7
Registered linux user #362635
****************************************
Reply With Quote
  #10  
Old 6th July 2004, 09:20 PM
PompeyBlue's Avatar
PompeyBlue Offline
Registered User
 
Join Date: Jun 2004
Location: Portsmouth, UK
Posts: 444
Quote:
Originally Posted by sailorsgh
Correct me if I am wrong, but I have heard that if you are using a router (I have a Linksys befsr41) that a firewall is not necessary. I have gone to grc.com(Shields Up!) and all is good all ports stealth..etc...I have tried this wIth both WIndows and FC2 with no firewall and the same, all ports are stealth...
Routers are such evil things for peer to peer communications that you are fairly secure from any type of incoming packet attack. That's not to say that some vulnerable open port hasn't packeted out, punched a whole in the router, which somebody could port scan to issue nasty packets to (although it's more unlikely).

The only thing they can't stop are client\server type attacks (i.e. you going to a web page and downloading some dodgy html\java code exploit) or retrieving email with trojans in. Although, I guess, you would want to use a virus scanner to prevent that threat.
Reply With Quote
  #11  
Old 7th July 2004, 12:45 AM
flea's Avatar
flea Offline
Registered User
 
Join Date: Apr 2004
Location: raleigh, NC
Age: 31
Posts: 97
just turn your router into a hub and go from there
__________________
fleabags. :cool:
gangster in training.
Reply With Quote
  #12  
Old 7th July 2004, 12:55 AM
Varkk Offline
Registered User
 
Join Date: Mar 2004
Location: New Zealand
Age: 34
Posts: 285
Quote:
Originally Posted by sailorsgh
Correct me if I am wrong, but I have heard that if you are using a router (I have a Linksys befsr41) that a firewall is not necessary. I have gone to grc.com(Shields Up!) and all is good all ports stealth..etc...I have tried this wIth both WIndows and FC2 with no firewall and the same, all ports are stealth...
Well we could do that here with our router, but the smoothwall provides so much more support for port forwarding, IPblocklists, logs of connections etc. Not to mention a local squid proxy cache. All of these things are hard to find in a consumer level router.
Reply With Quote
  #13  
Old 7th July 2004, 02:25 AM
usopso Offline
Registered User
 
Join Date: May 2004
Location: earth
Posts: 10
you should try Arno's iptables script which is BEST of all!sure it works with iptables and supports kernel 2.6xx version
__________________
open your mind,use open source
Reply With Quote
  #14  
Old 7th July 2004, 10:04 AM
sailor's Avatar
sailor Offline
Registered User
 
Join Date: Mar 2004
Location: San Antonio, Texas
Age: 55
Posts: 3,996
If I had another available and suitable computer to use as the firewall I might go that route with a smoothwall setup...
I guess its also important to know what is trying to contact the net from my box...of course I have more problems with my Windows in that regard...
__________________
sailor
Fedora 16, Mac OSX Snow Leopard, Windows 7
Registered linux user #362635
****************************************
Reply With Quote
  #15  
Old 8th July 2004, 10:00 AM
Algernon Offline
Registered User
 
Join Date: Jun 2004
Posts: 56
Personally I don't like bloat so I use LEAF ( http://www.leaf-project.org/ ) with a separate PC (486/50Mhz with 16MB memory and two network cards). Booting of a 1.44MB(1.68MB) floppy.
No HD and NO NOISE.

-M
Reply With Quote
Reply

Tags
fc2, firewall

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall aids Using Fedora 2 14th June 2006 11:46 AM
First firewall craigbass76 Security and Privacy 3 20th August 2005 01:10 AM
what firewall cederstrom Security and Privacy 8 19th July 2005 11:51 PM
Firewall trinimoses Using Fedora 2 19th July 2005 09:23 AM
Fedora firewall vs SUSE firewall claes Security and Privacy 6 1st February 2005 10:04 PM


Current GMT-time: 09:52 (Tuesday, 21-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat