security setup without firewall?



hi

I have been hearing from different sources that a truly good security setup does not require a firewall. Of course that depends on the situation for the system. but if one considers a single home computer, is it plausible to have basic security without a firewall?

The reason I am asking is that I am looking for the simplest way to centrally control which ports are open and for which adresses. The problem is that most firewall systems on linux are pretty complex, e.g. shorewall, and that makes it difficult to make it work properly.

I was initially thinking that setting hosts.deny/allow would cover a lot of ground. When I tested it, by setting deny: ALL:ALL, I found that SSH was affected but http was not. I also found that nmap finds all the ports open. Yhis suggest to me that if I dont use a firewall I have to separately configure all the different services to make a basic security config.

So the question is, is there a single file such as allow\deny that can be used to control visibility of ports and access in an easy way, or is a firewall the only real option for this (which mean that I would have to throw out shorewall and just use iptables directly)

tom
.



Relevant Pages

  • [REVS] Bypassing Client Application Protection Techniques
    ... Get your security news from a reliable source. ... protection programs. ... * Kerio Personal Firewall 4.0 ... And we got actually nothing in the field of client application ...
    (Securiteam)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Returned vulnerabilities, Messenger Spam, pls. HELP
    ... You should not enable XP's firewall if you are also running ... check for verification I achieved stealth status for all ports it can check. ... As a result for one or two days there was no Messenger Spam on my screen. ... But the messenger spam returned in a series and rechecked security did find ...
    (microsoft.public.windowsxp.security_admin)
  • Why hasnt Symantec addressed nastier Messenger spoofs
    ... Norton / Symantec has been silent on whether Norton Internet Security ... DSL firewall will stop these kinds of pop-ups. ... major ISPs and broadband systems. ...
    (comp.security.misc)
  • Re:RE : suggestions on a good firewall
    ... Subject: RE: suggestions on a good firewall ... CheckPoint does! ... with a url-filtering server. ... IT Technical Security Officer ...
    (Security-Basics)