Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts

Configure Netfilter Easily - Shorewall

Shorewall is a high-level tool for configuring Netfilter.

How Shorewall works?
You describe your firewall/gateway requirements using entries in a set of configuration files, Shorewall reads those configuration files and with the help of the iptables utility, Shorewall configures Netfilter to match your requirements.

Shorewall can be used on a dedicated firewall system, a multi-function gateway/router/server or on a standalone GNU/Linux system. Shorewall does not use Netfilter's ipchains compatibility mode; as a consequence, Shorewall can take advantage of Netfilter's connection state tracking capabilities to create a stateful firewall.

shorewall.net

DOWNLOAD Shorewall

Firewall automation tool for GNU/Linux


TuxFrw is a complete firewall automation tool for GNU/Linux, it consists of script files created to ease the way Linux IPTables firewall rules are configured.

With TuxFrw an user can configure his own Linux-based network firewall, simply passing some IP address numbers and other network utilization policies.

# Simple, high customizable firewall scripting framework;
# Open and close ports, deny forged traffic, stop flooding and stealth your services easily;
# Set up Network Address Translation for your LAN;
# Keep your DMZ away from attacks;

Download TuxFrw

Manage multiple firewalls using the same database of network objects with FirewallBuilder

Manage multiple firewalls using the same database of network objects with FirewallBuilder
With FirewallBuilder, system administrator will be able to manage multiple firewalls using the same database of network objects. A determinate change made to an object is immediately reflected in the policy of all firewalls using this object.

What is FirewallBuilder (from FirewallBuilder Website)
FirewallBuilder is a GUI firewall configuration and management tool that supports iptables (netfilter), ipfilter, pf, ipfw, Cisco PIX (FWSM, ASA) and Cisco routers extended access lists. Firewall Builder uses object-oriented approach, it helps administrator maintain a database of network objects and allows policy editing using simple drag-and-drop operations.




FirewallBuilder HOWTOS:
Installing OpenWrt on Linksys WRT54GSv1.1, by Chris Martin
How to use Firewall Builder to manage policy of the Linksys firewall running OpenWRT firmware
How to migrate objects from one data file to another
How to use built-in policy installer in Firewall Builder 2.0
Using fwb_install
How to make firewall load firewall policy after reboot – pf
How to make firewall load firewall policy after reboot – ipfw
How to make firewall load firewall policy after reboot – ipfilter
How to make firewall load firewall policy after reboot – iptables
How to restart firewall script when interface address changes
Documents, contributed by our users

How to Restore IPTABLES Automatically On Boot

This script posted by jawnsy on debian-administration.org loads the settings from $IPSTATE (by default /etc/iptables.conf) when you Boot.

"You have to save the rules manually; this ensures that you make sure your rules are working properly (i.e. doesn't block you from logging in remotely, for example) before you decide to save them.

You do this running the command: "iptables-save > /etc/iptables.conf" (or whatever file you have chosen to use as your $IPSTATE file)"

Read The full article and download the script at:
http://www.debian-administration.org/articles/615

How to configure a Transparent Proxy using Squid and ebtables

Related to the post "Download ebtalbes filtering tool" you can also read this excellent tutorial "Configuring a Transparent Proxy/Webcache in a Bridge using Squid and ebtables".

Read the full article

Download ebtalbes filtering tool

Download ebtables

From ebtalbes, website:

The ebtables program is a filtering tool for a bridging firewall. The filtering is focussed on the Link Layer Ethernet frame fields. Apart from filtering, it also gives the ability to alter the Ethernet MAC addresses and implement a brouter.
This website is also a reference for the Linux bridge-nf code, which gives Linux the functionality of a bridging IP/IPv6/ARP firewall, by letting iptables/ip6tables/arptables 'see' the bridged IPv4/IPv6/ARP packets. Both ebtables and bridge-nf are a part of the standard 2.6 kernel. A patch for the 2.4 stable kernel is maintained here, because enough people keep bugging me when Marcelo releases yet another 2.4 kernel.

What is ebtables
The ebtables utility enables basic Ethernet frame filtering on a Linux bridge, logging, MAC NAT and brouting. It only provides basic IP filtering, the full-fledged IP filtering on a Linux bridge is done with iptables. The so-called bridge-nf code makes iptables see the bridged IP packets and enables transparent IP NAT. The firewalling tools iptables and ebtables can be used together and are complementary. ebtables tries to provide the bridge firewalling that iptables cannot provide, namely the filtering of non-IP traffic.


Ebtables features:

Usage analogous to iptables.
Ethernet filtering.
MAC NAT: ability to alter the MAC Ethernet source and destination address. This can be useful in some very strange setups (a real-life example is available).
Brouting: decide which traffic to bridge between two interfaces and which traffic to route between the same two interfaces. The two interfaces belong to a logical bridge device but have their own IP address and can belong to a different subnet.
Pass packets to userspace programs, using netlink sockets (the ulog watcher).

What ebtables do?
- Ethernet protocol filtering.
- MAC address filtering.
- Simple IP header filtering.
- ARP header filtering.
- 802.1Q VLAN filtering.
- In/Out interface filtering (logical and physical device).
- MAC address nat.
- Logging.
- Frame counters.
- Ability to add, delete and insert rules; flush chains; zero counters.
- Brouter facility.
- Ability to atomically load a complete table, containing the rules you made, into the kernel. See the man page and the examples section.
- Support for user defined chains.
- Support for marking frames and matching marked frames.
- {Ip,Ip6,Arp}tables can filter bridged IPv4/IPv6/ARP packets, even when encapsulated in an 802.1Q VLAN header.
- All filtering, logging and NAT features of the 3 tools can therefore be used on bridged frames.
- Combined with ebtables, the bridge-nf code therefore makes Linux a very powerful transparent firewall.
- This enables, f.e., the creation of a transparent masquerading machine (i.e. all local hosts think they are directly connected to the Internet).
- Letting {ip,ip6,arp}tables see bridged traffic can be disabled using the appropriate proc entries, located in /proc/sys/net/bridge/. Also, letting the aforementioned firewall tools see 802.1Q VLAN encapsulated packets can be disabled with such a proc entry.

Basic ebtables filtering configuration

Howto Setup Firewall on Mandriva 2008

This video shows you how to setup your firewall on Mandriva 2008
Mandriva 2008 - Firewall Setup Video

Useful Netstat commands

Check the list of the top 10 using netstat:
# netstat -an | grep 'ESTABLISHED' | awk '{print $4}' | cut -d: -f1 | uniq -c | sort -rn | head -n 10

View all established connections using netstat:
# netstat -an | grep 'ESTABLISHED' | awk '{print $4}' | cut -d: -f1 | uniq -c | sort -rn

Check the largest number of established connections:
# netstat -an | grep 'ESTABLISHED' | awk '{print $4}' | cut -d: -f1 | uniq -c | sort -rn | head -n 1

Check each detail using netstat:
# netstat -an | grep 'ESTABLISHED' | awk '{print $4}' | cut -d: -f1 | uniq -c | sort -rn | more

You can show the port with nestat using:
# netstat -an | grep 'ESTABLISHED' | awk '{print $4}' | uniq -c | sort -rn

Script to daily email APF status

You are running APF on your server, but sometimes you think "is APF running fine?"
This script sends you an email with APF satus.

Log in to your server as root

Create the script:
# nano apf1.sh

Put this on the file:
#!/bin/bash

tail -200 /var/log/apf_log | mail -s "APF Status" you@yourdomain.com
Save and Exit

Make it executable:
# chmod 755 apfstatus.sh

Move it to "/etc/cron.daily" folder:
# mv apf1.sh /etc/cron.daily

You will receive now a daily email with APF status.

You can read this:
How to Install APF

COMODO - The best Free Windows Firewall

COMODO is at the time probably the best free firewall for Windows.



COMODO Description:
- Complete protection from Hackers, Spyware etc.
- Secures against internal and external attacks
- Host Intrusion Prevention System stops malware ever being installed
- Delivers total end-point security for Personal Computers and Networks

Download Comodo Firewall

Install DDoS Deflate

Description:
When you run this Perl script, it will then run an netstat command check how many times each IP is connected and if there are more then the number of connections you specified then it will automatically run a command in APF for the IP to be banned.

Installing:
wget http://www.inetbase.com/scripts/ddos/install.sh
chmod 0700 install.sh
./install.sh

Uninstalling:
wget http://www.inetbase.com/scripts/ddos/uninstall.ddos
chmod 0700 uninstall.ddos
./uninstall.ddos

Also read: How TO install APF Firewall

Installing CSF Firewall

Intalling CSF:
# wget http://www.configserver.com/free/csf.tgz
# tar zxf csf.tgz
# cd csf
# sh install.sh
Note:
If you are running APF you should disable it. You can do it with this script (inclued on csf.tgz):
# sh disable_apf_bfd.sh

You can modify config option directly on WHM or if you prefer edit /etc/csf/:
# nano /etc/csf

CSF includes:
  • Straight-forward SPI iptables firewall script
  • Daemon process that checks for login authentication failures for:
    • courier imap and pop3
    • ssh
    • non-ssl cpanel / whm / webmail (cPanel servers only)
    • pure-pftd
    • password protected web pages (htpasswd)
    • mod_security failures
  • POP3/IMAP login tracking to enforce logins per hour
  • SSH login notification
  • SU login notification
  • Excessive connection blocking
  • WHM configuration interface (cPanel servers only) or through Webmin
  • WHM iptables report log (cPanel servers only)
  • Easy upgrade between versions from within WHM (cPanel servers only) or through Webmin
  • Easy upgrade between versions from shell
  • A standard Webmin Module to configure csf is included in the distribution ready to install into Webmin - csfwebmin.tgz
  • Pre-configured to work on a cPanel server with all the standard cPanel ports open (cPanel servers only)
  • Auto-configures the SSH port if it's non-standard on installation
  • Block traffic on unused server IP addresses - helps reduce the risk to your server
  • Alert when end-user scripts sending excessive emails per hour - for identifying spamming scripts
  • Suspicious process reporting - reports potential exploits running on the server
  • Excessive user processes reporting
  • Excessive user process usage reporting and optional termination
  • Suspicious file reporting - reports potential exploit files in /tmp and similar directories
  • Directory and file watching - reports if a watched directory or a file changes
  • Block traffic on the DShield Block List and the Spamhaus DROP List
  • Pre-configured settings for Low, Medium or High firewall security (cPanel servers only)
  • Works with multiple ethernet devices
  • Server Security Check - Performs a basic security and settings check on the server (cPanel servers only)
  • Allow Dynamic DNS IP addresses - always allow your IP address even if it changes whenever you connect to the internet
  • Alert sent if server load average remains high for a specified length of time
  • mod_security log reporting (if installed)
  • Email relay tracking - tracks all email sent through the server and issues alerts for excessive usage (cPanel servers only)
  • IDS (Intrusion Detection System) - the last line of detection alerts you to changes to system and application binaries
Supported and Tested Operating Systems
- RedHat v7.3, v8.0, v9.0
- openSUSE v10
- RedHat Enterprise v3, v4, v5 Debian v3.1 (sarge)
- CentOS v3, v4, v5 Unbuntu v6.06 LTS
- Fedora Core v1, v2, v3, v4, v5, v6
- Tested on cPanel (except FCv6)

How TO install APF Firewall

"Advanced Policy Firewall (APF) is an iptables(netfilter) based firewall system designed around the essential needs of today's Internet deployed servers and the unique needs of custom deployed Linux installations. The configuration of APF is designed to be very informative and present the user with an easy to follow process, from top to bottom of the configuration file."
(http://rfxnetworks.com/apf.php)

How To install APF firewall
Login to your server as root, then:
# cd /usr/srcwget
http://rfxnetworks.com/downloads/apf-current.tar.gz
# tar -xvzf apf-current.tar.gz
# rm -f apf-current.tar.gz
# cd apf-*
# ./install.shcd /etc/apf

Port configuration:
Ports 2082 to port 2095 is mostly used by cpanel, and port 19638 is only use in ensim.


Edit conf.apf
# nano conf.apf

Common ingress (inbound) TCP IG_TCP_CPORTS="20,21,22,25,53,80,110,143,443,465,993,995,2082,2083,2086,2087,2095,2096,3306,10000,35000_35999"

Common ingress (inbound) UDP
IG_UDP_CPORTS="20,21,53,1040"

Exit and save and then restart apf:
# service apf start

If APF is functioning fine, edit the conf.apf
# nano conf.apf

Set the DEVM parameter to 0DEVM="0"

Now you can Restart APF, and is done:
# service apf restart