/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Thanks for answering, David.
"David A. Ranch" wrote:
> A few questions first:
>
> 1) How are you connected to the Inet? PPP? DSL? Static or dynamic IP
> address?
I am connected through cable, dynamic IP.
> 2) How are you loading the rc.firewall script?
Since I am running under Debian, I call the rc.firewall script from
/etc/init.d/network, after setting up the interfaces and doing some preliminary
stuff there (such as turnning on ip_forward, ip_dynaddr, setting up loopback,
adding the multicast route); the last line calls /etc/init.d/rc.firewall (which
is executable).
I noted that you make mention of a similar problem in your newest TrinityOS; I
use dhclient and it does not try to run the firewall script at all. However, I
think you are pointing out a concern that dhcp users may have generally but it is
beyond me what the cause is.
> Anyway, since it sounds like your firewall isn't running upon boot,
> you should be concerned why you have ports 1080, 12345, and 111
> open. This is BAD.
Very bad. But, I run /etc/init.d/rc.firewall manually a second time after any
reboot, and most of these ports were closed quite nicely. I tested my firewall
using www.secure-me.net -- a really good site, I have to recommend it-- and as a
result, I have added an explicit rule to reject on a some specific ports that
were found to still be open: 53 (I'm ussing SSH),139, 1026, 3128 (I am running a
squid proxy to cache web pages, anonymize, and block ads with ad-zapper).
Curiously, secure-me recommended I close 31337, which I did. As of now, by
running the script a second time manually, secure-me says I am invisible and
gives a score of zero, which is the best score the site gives.
secure-me still reports that 1080 (socks), 12345 and 12346 (Netbus) are there but
"filtered" which I also find odd because I don't have these ports enabled at all
in /etc/services or /etc/inetd.conf, or anything running (I think) that enables
them. What is "filtered" exactly -- decaf? 8-)
> Next, filtering in-bound pings is silly though its simple.
> You need to filter ICMP-ECHO destined to your external interface.
Well, it's interesting that you say that; I may be making an assumption about
icmp that is unwarranted. I had always thought that responding to pings was the
thing I wanted to avoid with the script-kiddies, because it let them know
_something_ was there. As I mentioned, secure-me.net still gives me a nice score,
but suggests that I not be pingable, except for my ISP. So to do this using
ipfwadm, is this right?:
ISP_net="x.x.x.x" - for @Home's network address they ping me from - is a range
possible here?
/sbin/ipfwadm -I -a accept -W $extif -P icmp -S $dgw/32 -D $extip/32 - sets up
default gateway (unchanged from TrinityOS)
/sbin/ipfwadm -I -a accept -W $extif -P icmp -S $ISP_net/0 -D $extip/32
/sbin/ipfwadm -I -a reject -W $extif -P icmp -S $universe/0 -D $extip/32
(I know ipchains would be good to move to, but I am waiting for the Debian
developers to make a 2.2 kernel that works on my machine).
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.