Networking Forums

Networking Forums > Computer Networking > Broadband > better firewalling rules for IPCOP/SmoothWall?

Reply
Thread Tools Display Modes

better firewalling rules for IPCOP/SmoothWall?

 
 
robert w hall
Guest
Posts: n/a

 
      09-26-2003, 08:06 AM
I've read recently that the default setup of SmoothWall & IPCOP should
be tightened, to allow less possibility of unintended outward traffic.

Anybody know where I can find a better set of iptables/ipchains rules to
apply(*), or an example of the required rule to adequately block the
return route. (I've tried a quick Google but found nothing relevant)
Bob

(*I'm personally interested in ipchains rules, for SmoothWall 1.0 -I
think latest IPCOP uses IpTables)
--
robert w hall
 
Reply With Quote
 
 
 
 
Julian Knight
Guest
Posts: n/a

 
      09-30-2003, 09:48 AM
Sorry, can't help with specifics as I don't use those tools but I can
say that it is safest to block everything and then just allow out the
ports you need from the machines you need. Particularly with reference
to ICQ and related chat type protocols, even email and web browsing if
you have a machine that acts as a local server.


From robert w hall:

>I've read recently that the default setup of SmoothWall & IPCOP should
>be tightened, to allow less possibility of unintended outward traffic.
>
>Anybody know where I can find a better set of iptables/ipchains rules to
>apply(*), or an example of the required rule to adequately block the
>return route. (I've tried a quick Google but found nothing relevant)
>Bob
>
>(*I'm personally interested in ipchains rules, for SmoothWall 1.0 -I
>think latest IPCOP uses IpTables)


--
Julian Knight,
/--------------------------------------------------------------------\
| *** Remove Anti Spam bits from address for Email Replies *** |
|Home Page: http://www.knightnet.org.uk/ |
|Location : Sheffield, South Yorkshire, United Kingdom. |
|Occupation: Security, Directory, Messaging, Network & PC Consultant |
\--------------------------------------------------------------------/
 
Reply With Quote
 
robert w hall
Guest
Posts: n/a

 
      09-30-2003, 11:26 AM
Thanks for the reply
Actually I guess I'm really after someone who understands 'ipchains'
If I mug up on the ipchains rules (which I find obscure!) and hack it
badly I'll probably totally lose my internet connection (which will make
it difficult to ask for help...)
Bob

(Top Posting so I get at least some response :-))
>>>


In article <9dNMLtB6FVe$(E-Mail Removed) PAM>,
Julian Knight <julian@[127.0.0.1]> writes
>Sorry, can't help with specifics as I don't use those tools but I can
>say that it is safest to block everything and then just allow out the
>ports you need from the machines you need. Particularly with reference
>to ICQ and related chat type protocols, even email and web browsing if
>you have a machine that acts as a local server.
>
>
> From robert w hall:
>
>>I've read recently that the default setup of SmoothWall & IPCOP should
>>be tightened, to allow less possibility of unintended outward traffic.
>>
>>Anybody know where I can find a better set of iptables/ipchains rules to
>>apply(*), or an example of the required rule to adequately block the
>>return route. (I've tried a quick Google but found nothing relevant)
>>Bob
>>
>>(*I'm personally interested in ipchains rules, for SmoothWall 1.0 -I
>>think latest IPCOP uses IpTables)

>


--
robert w hall
 
Reply With Quote
 
Tim
Guest
Posts: n/a

 
      09-30-2003, 12:05 PM
robert w hall wrote:
<snip>

> (Top Posting so I get at least some response :-))


You may not get the responses you'd like, though

tim

 
Reply With Quote
 
Huge
Guest
Posts: n/a

 
      09-30-2003, 12:59 PM
robert w hall <(E-Mail Removed)> writes:
>Thanks for the reply
>Actually I guess I'm really after someone who understands 'ipchains'
>If I mug up on the ipchains rules (which I find obscure!) and hack it
>badly I'll probably totally lose my internet connection (which will make
>it difficult to ask for help...)
>Bob
>
>(Top Posting so I get at least some response :-))


Depends if you think being killfiled is a response or not, I guess.

--
"The road to Paradise is through Intercourse."
The uk.transport FAQ; http://www.huge.org.uk/transport/FAQ.html
[email me at huge [at] huge [dot] org [dot] uk]


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
"Transparent" Mode in IPCop / smoothwall / MNF (real IP inside firewall) jcychk@gmail.com Linux Networking 3 08-09-2005 04:04 AM
Server 2003 VPN and smoothwall Myronboy Windows Networking 3 01-20-2004 11:50 PM
vpn through smoothwall myronboy Windows Networking 2 01-20-2004 10:13 PM
Appropriate Firewalling M2@M Linux Networking 1 01-11-2004 05:05 PM
Firewall (smoothwall) reports 'Potentially Bad Traffic' from 127.0.0.1:80... robert w hall Broadband 2 09-12-2003 11:29 AM



1 2 3 4 5 6 7 8 9 10 11