Linux server as it own firewall

From: James Puckett (jpuckett@ticom.com)
Date: 09/12/01


From: James Puckett <jpuckett@ticom.com>
To: focus-linux@securityfocus.com
Subject: Linux server as it own firewall
Date: Wed, 12 Sep 2001 13:25:21 -0400
Message-Id: <0109121325210B.19384@blackwell>

All,

        I am considering having the firewall for a Linux server I am building
running on the server itself using IPTables. This server will see very little
load, so performance will probably not be an issue. What I am wondering is,
what are the implications of having a Linux box on the internet running its
own firewall? The way I see it, if someone can manage to break into a locked
down firewall, he will not have too many problems getting into the machines
behind the firewall. On the other hand, if the attacks take a while to go
off, the extra time it takes to get into the server behind the FW could be
what saves the server if the intrusion is detected. I also wonder about the
obvious problem of having extra daemons on the firewall adding to the number
of exploitable holes on one machine.

        Overall I am really against the idea, but in the long run working this way
could save some money, and if it looks like the system won't be made too
insecure this could be a viable idea.

        Thoughts,

Thanks

-james



Relevant Pages

  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)
  • RE: Is this as bad as it seems?
    ... The network being protected by the router or firewall is still vulnerable to ... > circumvented - the administrator has explicitly allowed HTTP traffic on ... this exploit has the effect of allowing the attacker to send *INBOUND* HTTP ... The HTTP server (located on the internal network or anywhere else that is ...
    (Security-Basics)