Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Anyone use FWBuilder and Linux for their firewall?

Thread Tools
 
Search this Thread
 
Old 09 October 2003, 09:40 PM
  #2  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

Just download ipcop. It's based on the 2.4 kernel and works without all that piddling around
Old 10 October 2003, 08:17 AM
  #4  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

FWbuilder is absolutly brilliant!!!!

Linux Journal did a 2 part paper on this a few months ago and they rated it so highly I was expecting the pages to be stuck together.

I configure my IPTables by hand, but I did try FWBuilder once to see what script it spat out.

The result was brilliant. I was very impressed and I even tweaked my own script to incorporate a few ideas from that.

If you want I can scan in the full writeup from Linux Journal (yes I am sad and do keep all my old copies). It will be Monday now, as I don't have a scanner at home.

Verdict : A1
Old 10 October 2003, 08:30 AM
  #5  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

You need to edit IPTables manually, which is a bit of a sod...

Add the following to drop all icmp
/sbin/iptables -A CUSTOMINPUT -i <<RED DEVICE HERE>> -p icmp -j DROP

To drop pings, just add
/sbin/iptables -A CUSTOMINPUT -i <device> -p icmp --icmp-type 8 -j DROP

I think rc.firewall is the right place for these, or rc.local. Just remember to either reboot or source the script.
Old 10 October 2003, 01:12 PM
  #7  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

Its pretty simple to install. Basic ./configure, make, make install is all (if I remember correctly)

You will need a pretty good knowledge base of network protocols and network operations as there are a lot of buttons to click on

Oh, just a guess but you may need GTK installed for the GUI (again, can't remember exactly)
Old 10 October 2003, 01:44 PM
  #8  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

Good luck mate - I wonder if the ipcop devel team would be interested in a better point'n'click gui?
Old 10 October 2003, 02:13 PM
  #9  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

Am I right in thinking IPCop uses an html style gui?
Old 12 October 2003, 09:02 PM
  #11  
tuffer
Scooby Regular
 
tuffer's Avatar
 
Join Date: Oct 2002
Posts: 184
Likes: 0
Received 0 Likes on 0 Posts
Post

Have you tried Smoothwall? It is the original that IPCop project forked from. The latest version is pretty good, I have had one running on a client site for the last 2 years and it has only been rebooted a couple of times when I have applied patches.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
dantiel
General Technical
8
29 September 2015 11:33 PM
dsmith
Computer & Technology Related
13
02 July 2002 12:02 AM
dsmith
Computer & Technology Related
4
31 January 2002 09:50 AM
dsmith
Non Scooby Related
11
05 December 2001 03:03 PM



Quick Reply: Anyone use FWBuilder and Linux for their firewall?



All times are GMT +1. The time now is 01:47 AM.