/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
I have an odd problem. I am running ipmasq on a Debian 2.1 box, which is
routing and firewall for my network.
My firewall script (from the TrinityOS (tm) site) leaves ports 22 (ssh),
53 (domain), 80 (http), 111 (sunrpc) open, and "filtered" ports open on
1080 (socks), 12345 and 12346 (NetBus). (I have tested this from a
couple of security sites, such as secure-me.net). The firewall is
started on bootup, and it seems to be working: rc.firewall is called by
the /etc/init.d/network script in Debian (and it is executable).
The _second_ time I run the script from the command line, and then run
these security tools, the only ports left open are 53 (domain) and the
filtered ones. Why is this? Is the way I configured my firewall to be
engaged, incorrect? By running the firewall a second time, I have
noticed that the scans I have experienced from script kiddies has gone
way, way down, so I would like to make sure that the firewall is
properly engaged the first time.
Some other questions to enhance security:
1. Should I be concerned about the ports that are visible? -
2. Should I be concerned because my system responds to pings? Would
someone give me an ipmasq script that would limit responding to pings to
the @Home network (I lose my ip address if my box doesn't respond).
3. How do I fake out the OS of my system? I don't want people to be able
to "see" this.
I have tried to close these "holes" without success, by adding lines to
the firewall script, but only made the holes worse, and quickly reverted
to my working firewall. Help is greatly appreciated.
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.