/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Thanks for answering, David.

"David A. Ranch" wrote:

> A few questions first:
>
> 1) How are you connected to the Inet?  PPP?  DSL?  Static or dynamic IP
> address?

I am connected through cable, dynamic IP.

> 2) How are you loading the rc.firewall script?

Since I am running under Debian, I call the rc.firewall script from
/etc/init.d/network, after setting up the interfaces and doing some preliminary
stuff there (such as turnning on ip_forward, ip_dynaddr, setting up loopback,
adding the multicast route); the last line calls /etc/init.d/rc.firewall (which
is executable).

I noted that you make mention of a similar problem in your newest TrinityOS; I
use dhclient and it does not try to run the firewall script at all. However, I
think you are pointing out a concern that dhcp users may have generally but it is
beyond me what the cause is.

> Anyway, since it sounds like your firewall isn't running upon boot,
> you should be concerned why you have ports 1080, 12345, and 111
> open.  This is BAD.

Very bad. But, I run /etc/init.d/rc.firewall manually a second time after any
reboot, and most of these ports were closed quite nicely. I tested my firewall
using www.secure-me.net -- a really good site, I have to recommend it-- and as a
result, I have added an explicit rule to reject on a some specific ports that
were found to still be open: 53 (I'm ussing SSH),139, 1026, 3128 (I am running a
squid proxy to cache web pages, anonymize, and block ads with ad-zapper).
Curiously, secure-me recommended I close 31337, which I did. As of now, by
running the script a second time manually, secure-me says I am invisible and
gives a score of zero, which is  the best score the site gives.

secure-me still reports that 1080 (socks), 12345 and 12346 (Netbus) are there but
"filtered" which I also find odd because I don't have these ports enabled at all
in /etc/services or /etc/inetd.conf, or anything running (I think) that enables
them. What is "filtered" exactly -- decaf? 8-)

> Next, filtering in-bound pings is silly though its simple.
> You need to filter ICMP-ECHO destined to your external interface.

Well, it's interesting that you say that; I may be making an assumption about
icmp that is unwarranted. I had always thought that responding to pings was the
thing I wanted to avoid with the script-kiddies, because it let them know
_something_ was there. As I mentioned, secure-me.net still gives me a nice score,
but suggests that I not be pingable, except for my ISP. So to do this using
ipfwadm, is this right?:

ISP_net="x.x.x.x" - for @Home's network address they ping me from - is a range
possible here?
/sbin/ipfwadm -I -a accept -W $extif -P icmp -S $dgw/32 -D $extip/32 - sets up
default gateway (unchanged from TrinityOS)
/sbin/ipfwadm -I -a accept -W $extif -P icmp -S $ISP_net/0 -D $extip/32
/sbin/ipfwadm -I -a reject -W $extif -P icmp -S $universe/0 -D $extip/32

(I know ipchains would be good to move to, but I am waiting for the Debian
developers to make a 2.2 kernel that works on my machine).

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to