Ask your questions here.
Tue Sep 17, 2013 2:35 am
I am looking at iptables.
I have looked here:
https://wiki.debian.org/iptablesand
http://www.linuxhomenetworking.com/wiki ... troductionand also here (German):
http://wiki.ubuntuusers.de/iptables2?redirect=noI mainly do this to enhance my understanding of networking.
I think i got the main idea of iptables, but now:
I go no clue what rules i would want to set at all.
Anyone can offer some general thoughts on the subject?
Tue Sep 17, 2013 10:51 am
I know very little about iptables, and it's been a while since I've done anything with it, but I thought that if you reject or drop all inbound traffic, you had to do that before you allowed any specific inbound traffic, because the rules are executed in order. That's not how the example at the wiki is written. Have you tested that set of rules?
And I'm also under the impression that dropping inbound traffic is safer than rejecting it, because you don't want to acknowledge your existence to crackers by responding to them with a rejection.
One thing you could try is to install a firewall package like shorewall or guarddog(?) and study the default rules that it uses. And a word of advice: if you happen to have a windows box running on the local network, make sure you divert all firewall messages to a separate log file, or your system logs will be cluttered with firewall messages. Cluttered is maybe not a strong enough word to describe it.
Tue Sep 17, 2013 6:43 pm
Thanks.
No, i haven't used those rules.
I read the how-to's and fiddled a bit on the cli.
Then i thought: What to do with that ... and there is nothing i can come up with.
Then i thought i would ask if there might be any reason to use it at all.
I really only try to get my head in it, i doubt i will need it.
What i could do is this:
server is visible on the internet and has ssh.
I disable connecting from the server via ssh to any other machine and always ssh from other machines to the server (on the other hand i usually got sshd disabled on the other machines ... mhhh).
Anyway, that might be a use for it (without further thinking).
In the meantime my second harddisk, where my OS is installed, gives clear signals of dying, so i will have to take care of that first)
btw: Do you have notes how to install encrypted without lvm with the debian installer somehwere?
(PS: i just went for it, and installing encrypted was straight forward this time - i could remember the basic steps from last time).
Sat Oct 12, 2013 5:48 am
tested the cli version, and it made a bootable iso. Haven't tested the gui version yet, but it didn't have the bug. Only made a few minor changes.
Powered by phpBB © phpBB Group.
phpBB Mobile / SEO by Artodia.