Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 8th March 2004, 03:05 PM
svarreby Offline
Registered User
 
Join Date: Feb 2004
Location: Sundsvall, Sweden
Posts: 64
Hardening my LAN ... what route should I take?

I am going to buy a cheap Duron/Celeron box next week who's only function would be to keep everything out of my LAN. I want to be able to set permissions for every digital packet that is destinated to my cables

What's the easiest way of accomplish this (ClarkConnect/IPCop/SmoothWall)?

Is it better to go the long way and start building it by hand (i.e install a stripped down distro and build it up from there)?

And if it's easy to set up, do I have to "thumb" on the security level?

What do I want to do? Well, pretty much everything I'm afraid

Firewall (IPTables), NAT, Routing, antivirus, anti-spam, squid ... you name it.

PS I'm no TCP/IP magician but I've got both time and motivation (and I'll hope that this will do it
Reply With Quote
  #2  
Old 9th March 2004, 03:09 AM
Bana's Avatar
Bana Offline
Retired Community Manager
 
Join Date: Feb 2004
Location: Austin, Texas
Age: 26
Posts: 581
Hmm, I would recommend smoothwall although it may not do ALL of the stuff you intend. If you have the time and ambition then I would Heartily suggest just slapping a minimal fedoraC1 install and building it together piece by piece, you will become the networking master and will be able to use it like a third arm to obey your wishes. If you don't have quite that much time you could install smoothwall and then poke around and see what is happening and try editing and configing it to your specs.

But by all means, if you are short on time and you want a slick, http interface, go with Smoothwall

(Now that I see the bottom line of your post I would recommend the bottom up install, there's nothing like jumping headfirst into the river to find out whats in it)
__________________
http://coolhands.blogspot.com/
binarybana AT gmail.com
Reply With Quote
  #3  
Old 9th March 2004, 01:58 PM
Ug's Avatar
Ug Offline
Retired Community Manager
 
Join Date: Feb 2004
Posts: 2,999
(In English: you have more control that way)
__________________
gareth@fedoraforum.org
Registered Linux User # 301555
garethrussell.net


Please adhere to the FedoraForum Guidelines.
Reply With Quote
  #4  
Old 9th March 2004, 09:48 PM
Thoreau's Avatar
Thoreau Offline
Registered User
 
Join Date: Mar 2004
Location: Kalamazoo, Michigan
Age: 30
Posts: 410
smoothwall is rock solid, but it takes over the whole drive if you like it or not. Heard that Clark Connect is pretty to get going, is this true?

If you can going to go with the mini-FC1 install, and want to do Iptables, may i suggest doing it on paper 1st? No don't write out all the commands...just get everything in order. trust me it'll be easier.
__________________
Things do not change; we change.
HDT

"Do I understand your question, man, is it hopeless and forlorn?" Bob Dylan

I disapprove of what you say, but I will defend to the death your right to say it.
-- The Friends of Voltaire, 1906

My NcpMount script for Netware servers
http://forums.fedoraforum.org/forum/showpost.php?p=544473&postcount=8
Thanks to: Brunson & Ibbo
Reply With Quote
  #5  
Old 9th March 2004, 11:20 PM
Ug's Avatar
Ug Offline
Retired Community Manager
 
Join Date: Feb 2004
Posts: 2,999
Planning being the key, i think is what Thoreau is suggesting.
__________________
gareth@fedoraforum.org
Registered Linux User # 301555
garethrussell.net


Please adhere to the FedoraForum Guidelines.
Reply With Quote
  #6  
Old 10th March 2004, 01:59 AM
Jman Offline
Registered User
 
Join Date: Mar 2004
Location: Minnesota, USA
Age: 27
Posts: 7,909
If you are using an existing distro, strip it down as much as possible. Only allow those services you need. In Fedora, System Settings > Server Settings > Services will help you switch these off. Use multiple firewalls if possible. Have a firewall on both the router machine and the clients. Run ethereal to determine what's on your network, and nmap to find out what ports are open.

In general, be as paranoid as possible. They're out to get you. Gotta go, have to check the defenses.
Reply With Quote
  #7  
Old 10th March 2004, 02:21 PM
Ug's Avatar
Ug Offline
Retired Community Manager
 
Join Date: Feb 2004
Posts: 2,999
I suppose its one advantage of dial-up, that you get a different IP for every connection.

So it makes it hard for someone to specifically target you.
__________________
gareth@fedoraforum.org
Registered Linux User # 301555
garethrussell.net


Please adhere to the FedoraForum Guidelines.
Reply With Quote
  #8  
Old 18th March 2004, 08:52 PM
Prometheus's Avatar
Prometheus Offline
Registered User
 
Join Date: Mar 2004
Location: Michigan, USA
Posts: 374
id personally go with smoothwall, because its setup right out of the box (so to speak). There arent as many options, but if you have the knowhow or the will, go for a stripped down distro. Then if you get bored, you can turn it into an FTP or a fileserver that people outside the network can see if you do it right
__________________
Registered Linux User #371104

Become a Registered Linux User Here
Reply With Quote
Reply

Tags
hardening, lan, route

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help on hardening Apache? backroger Servers & Networking 10 15th January 2005 11:30 PM


Current GMT-time: 13:14 (Tuesday, 21-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat