Re: Checking FC2 Iptables firewall config for PPPoE-enabled Gateway

From: Walter Schiessberg (nospam.news_at_arcor.de)
Date: 08/29/04

  • Next message: Neil Zanella: "Re: xhost/xauth stuff: question"
    Date: Sun, 29 Aug 2004 23:55:59 +0200
    
    

    Max wrote on 29.08.2004 23:30:

    > Greetings,
    >
    > Recently, I completed setting up an FC2-enabled server as a home gateway.
    >
    > Its connection to the Internet is by way of Verizon's PPPoE DSL. The
    > external Westell modem connects to eth0; the home LAN connects to eth1.
    >
    > Everything seems to be communicating correctly. The concern I have and
    > the request I make of the list is to review the iptables setting for the
    > gateway.
    [Configuration]
    >
    > My concern is how exposed/vulnerable is the above gateway configuration?

    Quite.
    - You're shure you have the following /public/ services: webserver, SSH,
    FTP, and mailserver?
    If not, or if you don't know what I'm talking about, remove the lines
    containing "state NEW ... ACCEPT".
    - 127.127.1.0 is local clock reference and has nothing to do with
    firewalling.
    And more...

    Better you look here
    <http://www.yolinux.com/TUTORIALS/LinuxTutorialIptablesNetworkGateway.html>
    or here <http://www.linuxguruz.com/iptables/> before connecting your
    machine to the internet.

    Walter


  • Next message: Neil Zanella: "Re: xhost/xauth stuff: question"

    Relevant Pages

    • Re: Internet Gateway
      ... the network services for gateway, and all seems back to normal (well, I then ... connection', and this was the only connection that was ever enabled. ... However, today there has appeared another connection, under Internet ...
      (microsoft.public.windowsxp.network_web)
    • Re: Firewall/AV Question about WinXP Connection While Not Logged On
      ... because the gateway machine still has ZoneAlarm running as a service ... > an Internet Connection Sharing gateway for a small home network. ... > - Computer A's user logs off his account...but keeps the modem ...
      (comp.security.firewalls)
    • Re: ISA dropping Internet Gateway
      ... Gateway - Switch of Internal LAN - PCs inside LAN ... Limsy the noob ... ... router with internet connection) keeps dying. ...
      (microsoft.public.isa)
    • Re: ICS Internet Gateway not connecting.
      ... The Inertnet Gateway in the Network Connection Control Panel say ... IE7 cannot get out to the internet, ... The Internet Gateway is your broadband router. ...
      (microsoft.public.windowsxp.network_web)
    • Re: Using SBS2K3 as dial-up "ISP" for users
      ... > gateway in this situation... ... > (Haven't actually done this myself, only enabling Internet ... You would have to uncheck the 'use ... >>> connection for users that will allow them to surf the ...
      (microsoft.public.windows.server.sbs)