SEARCH

Enter your search query in the box above ^, or use the forum search tool.

You are not logged in.

#1 2009-03-24 14:20:45

Mich
#! Member
Registered: 2009-01-22
Posts: 97

Comes with a Firewall Setup

Remembered reading somewhere that Mepis comes with GuardDog pre-configured to a "common" setting.
Opensuse also comes with something similar.

It would be attractive for #! to come with a pre-configured firewall for the next release.  big_smile

Offline

Be excellent to each other!

#2 2009-03-24 23:38:02

flicck
#! Member
Registered: 2008-12-26
Posts: 87

Re: Comes with a Firewall Setup

There is a pretty handy walkthrough of gufw from Ubuntugeek :

http://www.ubuntugeek.com/gufw-simple-g … ewall.html

On the other hand I just "sudo ufw enable && sudo ufw default deny" after first boot of a fresh install.

Not sure how much or how little of a pain it would be for corenominal to have that configured out of the box, and what issues it may or may not raise for some users.

Offline

#3 2009-03-25 00:36:37

Mich
#! Member
Registered: 2009-01-22
Posts: 97

Re: Comes with a Firewall Setup

Ahh... good to learn that you did some magical stuff after a first install.
However, not every user knows how to goes about doing that.

Was thinking that since #! is fully operational on install, it would be interesting and beneficial to give users a good start with a default installation big_smile

Offline

#4 2009-03-25 01:38:44

anonymous
The Mystery Member
From: Arch Linux Forums
Registered: 2008-11-29
Posts: 8,928

Re: Comes with a Firewall Setup

I just tried gufw and I found that it automatically detected my p2p applications. I just select the program, click Add, and gufw adds the correct port. How cool is that?


Note: ** Please read before posting **

BTW if you wish to contact me, send me an e-mail instead of a PM.

Offline

#5 2009-03-25 02:53:27

kBang
#! Die Hard
From: Calera, AL, USA
Registered: 2009-01-06
Posts: 774

Re: Comes with a Firewall Setup

anonymous wrote:

I just tried gufw and I found that it automatically detected my p2p applications. I just select the program, click Add, and gufw adds the correct port. How cool is that?

Extremely cool?  I would say so.  One of the reasons I avoid firewalls in Linux is p2p and my avoidance to learn how to set up ip tables.


I view KDE like I view snow. It looks fun and marvelous, it's fun to play in, but after a while I just want someone to take it all away.

Offline

#6 2009-03-25 10:47:28

needcoffee
Member
Registered: 2009-03-15
Posts: 39

Re: Comes with a Firewall Setup

You can also use firestarter (in repository, just as a hint).

Offline

#7 2009-03-25 12:06:16

Moncky
Member
From: Scotland, UK
Registered: 2009-03-22
Posts: 23
Website

Re: Comes with a Firewall Setup

Whilst its a good idea do you really want someone else making an arbitrary decision as to what ports you want to have open or closed on your firewall, more so do you want that person choosing what firewall application does that?  Whether it be IP tables or not?

My personal preference is to have a blank firewall and build it myself.

Perhaps a solution would be for either a script that will configure your firewall for you post install, or for a HOWTO on setting up your firewall in a specific way?


Don't remember how to do it; just that it can be done! Google will know how.

Offline

#8 2009-06-18 07:06:25

jackbang
#! CrunchBanger
Registered: 2009-05-28
Posts: 244

Re: Comes with a Firewall Setup

The problem is people won't build their own firewall.

Even experienced users can forget - I did.  A good firewall should deny everything and stay hidden away, so it's quite possible when you build a new system that you'll just assume everything is locked up.  I remember building a slackware or similar system sometime in the mid-late 90s, and forgot to setup the firewall.  It got a worm within about 10 minutes of being hooked up to the internet, or possibly something nasty was on the local network.

The gufw function of knowing which ports are required by apps (I guess they maintain a database) is extremely cool and user-friendly.  The distro should perhaps come with everything initially locked down, and generate a message that prompts the user to go and look at their firewall setup, the first time any transgressions are attempted - ie the first time you run a p2p app or whatever.  Maybe web-browsing should be pre-configured, as that's so essential.

Offline

#9 2009-06-18 11:44:39

fhsm
#! Junkie
From: New Hampshire, USA
Registered: 2009-01-05
Posts: 443

Re: Comes with a Firewall Setup

If you are looking for help building a firewall of iptables but not so much help that you don't learn anything have a look at FireHOL.


FHSM: avoid vowels and exotic consonants and you'll get your handle every time.  identi.ca

Offline

#10 2009-06-18 16:29:12

illumin8
#! Junkie
From: Seattle
Registered: 2009-05-30
Posts: 400
Website

Re: Comes with a Firewall Setup

flicck wrote:

There is a pretty handy walkthrough of gufw from Ubuntugeek :

http://www.ubuntugeek.com/gufw-simple-g … ewall.html

On the other hand I just "sudo ufw enable && sudo ufw default deny" after first boot of a fresh install.

thanks for the link.
have you had any issues with conky with ufw default deny settings?

flicck wrote:

Not sure how much or how little of a pain it would be for corenominal to have that configured out of the box, and what issues it may or may not raise for some users.

ok fellow #!ers whom i love, im not trying to sound condecending here..really.
but honestly do we really need someone to preconfigure our firewall for us?
it sort of sounds like having someone come over to put the toilet paper on the roll.

im still learning...
i installed gufw last night, and its FAIRLY uncomplicated, not entirely up to its name, but i can learn. id like to know more about iptables..not sure why that seems so daunting...its pretty well documented isnt it?


Website    500px     DeviantArt
God never ends anything on a negative; God always ends on a positive. -- Edwin Louis Cole --

Offline

#11 2009-06-22 08:56:07

Roybot
New Member
From: Europe
Registered: 2009-06-18
Posts: 6

Re: Comes with a Firewall Setup

Im gonna go ahead and borrow this thread to ask. How can I make gufw autostart? the "autostart with session" checkbox in edit > preferences is grayed out.


Asus Eee 1000H 160GB HDD 2GB RAM 1.6Ghz ATOM CPU XP/#eee dual-boot

Offline

#12 2009-06-22 10:07:42

jackbang
#! CrunchBanger
Registered: 2009-05-28
Posts: 244

Re: Comes with a Firewall Setup

I think gufw is only for configuring the firewall, which is esentially part of the kernel (iptrables).  As long as you have ticked "enable", the firewall settings that you have configured with gufw are automatically setup at bot time (by the "ufw" startup script int /etc/init.d).  The documentaion could be clearer on this point.
If you genuinely wanted the graphic configuration app to automatically start, I guess you'd add it to .config/openbox/autostart.sh

Last edited by jackbang (2009-06-22 10:16:11)

Offline

#13 2009-06-23 07:38:01

Tuxfriend
Member
From: Hamburg, Germany
Registered: 2009-06-10
Posts: 41

Re: Comes with a Firewall Setup

What kind of firewall is recommended? People coming from windows want something that blob 1 requester per second to allow or deny things that the user did not understand. Then they feel secure, so xandros put a commercial antivirus to their distro:lol:
We can harden a linux distri (bastille) and / or set a firewall in front of running services. Both are'nt easy tasks for a plain user, more an admin job. There are less running services in crunch that really need such thing;)

Offline

#14 2009-06-23 13:39:23

anonymous
The Mystery Member
From: Arch Linux Forums
Registered: 2008-11-29
Posts: 8,928

Re: Comes with a Firewall Setup

Well Linux has the iptables firewall. Firestarter, GuardDog, and Gufw are just front-ends to configure it.

I like gufw for reason I mentioned earlier.


Note: ** Please read before posting **

BTW if you wish to contact me, send me an e-mail instead of a PM.

Offline

#15 2009-06-25 06:55:45

Tuxfriend
Member
From: Hamburg, Germany
Registered: 2009-06-10
Posts: 41

Re: Comes with a Firewall Setup

Hello

possible that a firewall in base setup will come.

http://brainstorm.ubuntu.com/?keywords=firewall&tags=

Tuxfriend

Offline

#16 2009-07-05 08:30:04

illumin8
#! Junkie
From: Seattle
Registered: 2009-05-30
Posts: 400
Website

Re: Comes with a Firewall Setup

Roybot wrote:

Im gonna go ahead and borrow this thread to ask. How can I make gufw autostart? the "autostart with session" checkbox in edit > preferences is grayed out.

Try adding

(sleep 1s && gufw) &

to the bottom of your autostart.sh

Preferences>Openbox Config>edit autostart.sh


Website    500px     DeviantArt
God never ends anything on a negative; God always ends on a positive. -- Edwin Louis Cole --

Offline

#17 2009-07-05 13:02:06

FiniteStateMachine
Part of the Machine
From: Ontario, Canada
Registered: 2009-06-29
Posts: 1,489

Re: Comes with a Firewall Setup

Personally, the firewall on my router is all I've ever needed, even running Windows.
I for one would be against having a default firewall with #!


just call me...
~FSM~

Offline

Board footer

Powered by FluxBB

Copyright © 2012 CrunchBang Linux.
Proudly powered by Debian. Hosted by Linode.
Debian is a registered trademark of Software in the Public Interest, Inc.

Debian Logo