Recent Articles

Using GUI To Control Your Linux Experience
GUI allows users to navigate and interact with their computer by using a mouse to "point," "click," and "drag" icons and other data around on the screen, instead of typing in commands. We've been advocating the...

Best-Practices Of Pro Linux Users
There would have been one or more reasons which would have tempted each one of us to try Linux, and some of us just never looked back. Few would have probably turned out to be Linux professionals, while others...

Open Source Foundations: Jim Zemlin Interviews...
The last Linux Foundation's installment in their Open Voices podcast series went live yesterday, featuring Mitchell Baker, chairperson of the Mozilla Foundation...

Choosing Linux Over Vista
Linux enthusiasts have always touted for Linux to be one of the best operating systems ever. Their voice grew shriller with the advent of Microsoft Windows Vista in the market. There have been quite a few times that...

How To Boot Up Linux Faster
You don't need to have a wireless kernel module loaded if you're on Ethernet LAN. This task is complex and will require a kernel recompilation, which unfortunately is not the easiest task to accomplish. We've seen and...

Thinking About Career In Linux?
The other night, a good question popped out of my head - How many of the geek teenagers wish to work on closed source technology today? It's been pretty ubiquitous for the computer freaks to turn to Linux/OSS, for...



WebProWire.com
TechnologySearchAdvertisingSocialFinancialLegal
Latest News on: WebProWire.com

Some Cut Back on Prescription... NYT > U.S.
Steve Jobs on Netbooks: "We've Got Gizmodo
Contest: Make Art From Starbucks... Wired Top Stories
Macworld hotel booking under the... The Unofficial...
SanDisk, McAfee intro secure USB... Electronista

10.22.08

Linux Gets A FireStarter

By Brajeshwar Oinam

Irrespective of the operating system, intrusion is one of the key concerns for computers connected to a network. Firewalls, as a matter of fact provide a resistance to this, if not a fool proof protection.

Black hats and white hats have always had a tug-of-war over intrusion detection techniques. Firewalls, as a matter of fact provide a resistance to this, if not a fool proof protection. Firewalls may be a hardware device or a software program used to filter information coming from within or outside the outside network into your private network or your workstation. Firewall may not be the best and the sole way to be secured on a network, but does act like the first cover against most of the network based attacks.

While hunting out for a firewall application to safe guard my Linux installation, I came across a good firewall named Firestarter for Linux. It has an intuitive graphical interface which allows you to configure the firewall in Linux using built in IPtables/IPchains utilities.

Firestarter is a powerful and user friendly firewall beneficial for both Linux desktop users and System Administrators. We shall check out the installation configuration of Firestarter on your Linux machine to help shield your data.

To do a terminal install, fire the run pop-up and type: $sudo apt-get install firestarter

Planet Alpha Dedicated Servers

If things go fine, you'll have Firestarter installed in few keystrokes. You may do the same using any of the alternative ways to install an application, discussed previously in one of my articles.

Setting up Firestarter

Go to System > Administrator > Firestarter (for Ubuntu)

It will allow you to setup your initial configuration when you run the Firestarter for the very first time. Initial steps consist of detection of network devices and selection of one. You also get an option of enabling dial out for modem users and that for for IP address assigned via DHCP.

Do check your routers' setting if you are using DHCP to assign local address. After checking all the options according to your need, click forward, you'll be asked for Internet connection sharing. Enable it if your system is on a network. Select the device type - hub/switch. Save your settings.

Get back to the main application window which consists of three tabs - Status, Events & Policy. The status indicator shows whether the Firestarter is active, disabled or locked. Event shows the list of attempted connections that it has blocked. The entries listed in red should be focused. You can visualize the rules for your firewall in the Policy window. It also allows you to create your own policies including options to enable or disable inbound/outbound traffic. These rules can be applied on hosts/ports.

There are primarily 3 inbound policy groups:

• Allow connections from hosts- It will allow the traffic from the host which can be predefined by the user as a trusted source.

• Allow service- It consist of two parameters - service and target. User can enter a name manually or Firestarter will try to determine the service name itself. The target maybe: Anyone, LAN clients, or a user specified IP, host/network.

• Forward service- It is only active if the Internet Connection Sharing is enabled.

Permissive mode allows the user to specify rules that limit outbound connections. Restrictive mode permits you to specify which connections are allowed to have outbound communication.
In order to experience some advanced features, you may go to Preferences.

Firestarter doesn't really affect your work real-estate as you can minimize it to the system tray by exiting the application and it will notify you by turning its icon to red when a suspicious block alert is encountered. ICMP filtering provides a way to send simple messages containing information or errors.

Options like Echo Request and Echo Reply tells how your firewall handles pings. To block incoming pings, click on Echo reply. Traceroute prevents your machine from being traced via trace route. Tos filtering allows you to set priority on the use of network traffic.

Overall, Firestarter happens to be a great firewall for most users. Do check it out!

Comments


About the Author:
Brajeshwar is an ace digerati and an ardent believer of KISS (Keep It Simple Stupid), he envisions pushing the technical envelope time and again for the betterment of commercial and practical applications.

http://www.brajeshwar.com/
LinuxProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com DevWebPro.com


About LinuxProNews
LinuxProNews is a collection of news and commentary designed to keep you in step with the ever evolving landscape of Linux environments. Opensource News and Advice for Linux Professionals




-- LinuxProNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2008 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article



Opensource News and Advice for Linux Professionals LinuxProNews News Archives About Us Feedback LinuxProNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact