Gentoo Archives: gentoo-amd64

From: Justin Krejci <jus@×××××××××××.com>
To: gentoo-amd64@l.g.o
Subject: Re: [gentoo-amd64] firewall
Date: Fri, 23 Dec 2005 11:27:57
Message-Id: 200512230526.16340.jus@krytosvirus.com
1 Firestarter to me was like using a ZoneAlarm type of windows firewall program.
2 It was very super easy to configure but not very flexible. I could not figure
3 out how to specify UDP vs TCP on rules. This seemed like a great program for
4 your average run of the mill home/desktop user.
5
6 For a GUI I settled on Kmyfirewall as it was extraordinarily easy to configure
7 and use once I learned the basics of how iptables worked. I also wrote a perl
8 script to automatically block IP addresses of hosts that do brute force SSH
9 attempts. The IP addresses are automatically unblocked after 1 day. Every
10 time a change is made it sends out an email. This has really helped to keep
11 my log files cleaner instead of seeing 500 failed login attempts in a 3 hour
12 span from one IP address, then multiply that by 1-5 IP addresses per day.
13
14 Note Kmyfirewall is very nice but is still considered beta and it shows but it
15 is not broken in any way that I can tell, just the interface has a couple of
16 small bugs AFAICT.
17
18 On Thursday 22 December 2005 05:17 am, Gavin Seddon wrote:
19 > It's alright for some. I eat lunch with a couple of dogs (canine).
20 > Gavin
21 >
22 > On Wed, 2005-12-21 at 09:01 -0800, Steve Herber wrote:
23 > > I would recommend you use Shorewall for an easy way to configure and
24 > > manage you iptables based linux firewall. The documentation is
25 > > excellent. Plus, I like to have lunch with the author.
26 > >
27 > > shorewall.net
28 > >
29 > > Steve Herber herber@×××××.com work: 206-221-7262
30 > > Security Engineer, UW Medicine, IT Services home: 425-454-2399
31 > >
32 > > On Wed, 21 Dec 2005, Gavin Seddon wrote:
33 > > > Hi,
34 > > > I have merged iptables. Will they start at boot and is there a link
35 > > > for configuring on Gentoo?
36 > > > Thanks.
37 > > > --
38 > > > Dr Gavin Seddon
39 > > > School of Pharmacy and Pharmaceutical Sciences
40 > > > University of Manchester
41 > > > Oxford Road, Manchester
42 > > > M13 9PL, U.K.
43 > > >
44 > > > --
45 > > > gentoo-amd64@g.o mailing list
46 >
47 > --
48 > Dr Gavin Seddon
49 > School of Pharmacy and Pharmaceutical Sciences
50 > University of Manchester
51 > Oxford Road, Manchester
52 > M13 9PL, U.K.
53 --
54 gentoo-amd64@g.o mailing list

Replies

Subject Author
Re: [gentoo-amd64] firewall Gavin Seddon <gavin.m.seddon@×××××××××××××.uk>