/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>Since I am running under Debian, I call the rc.firewall script from
>/etc/init.d/network, after setting up the interfaces and doing some
preliminary
>stuff there (such as turnning on ip_forward, ip_dynaddr, setting up loopback,
>adding the multicast route); the last line calls /etc/init.d/rc.firewall
(which
>is executable).
>
>I noted that you make mention of a similar problem in your newest TrinityOS; I
>use dhclient and it does not try to run the firewall script at all. However, I
>think you are pointing out a concern that dhcp users may have generally but it
is
>beyond me what the cause is.
I haven't used DHclient but I might need to try it out since dhcpcd doesn't
allow you to alter the TCP sliding window for performance issues. Kinda
blows.
>Very bad. But, I run /etc/init.d/rc.firewall manually a second time after any
>reboot, and most of these ports were closed quite nicely. I tested my firewall
>using www.secure-me.net -- a really good site, I have to recommend it-- and as
a
>result, I have added an explicit rule to reject on a some specific ports that
>were found to still be open: 53 (I'm ussing SSH),139, 1026, 3128 (I am running
a
>squid proxy to cache web pages, anonymize, and block ads with ad-zapper).
It sounds like the firewall isn't being loaded from your
/etc/rc.d/init.d/network
script. Hunt this one down.
>Curiously, secure-me recommended I close 31337, which I did. As of now, by
>running the script a second time manually, secure-me says I am invisible and
>gives a score of zero, which is the best score the site gives.
Yup.. the TrinityOS firewall is pretty anal. :)
>secure-me still reports that 1080 (socks), 12345 and 12346 (Netbus) are there
but
>"filtered" which I also find odd because I don't have these ports enabled at
all
>in /etc/services or /etc/inetd.conf, or anything running (I think) that
enables
>them. What is "filtered" exactly -- decaf? 8-)
Dunno. What is your IP address? Can I port scan you?
>Well, it's interesting that you say that; I may be making an assumption about
>icmp that is unwarranted. I had always thought that responding to pings was
the
>thing I wanted to avoid with the script-kiddies, because it let them know
>_something_ was there. As I mentioned, secure-me.net still gives me a nice
score,
>but suggests that I not be pingable, except for my ISP. So to do this using
>ipfwadm, is this right?:
Yeah.. you would use either IPFWADM for old kernels or IPCHAINS for new ones.
But, its not going to make you less vunderable. When hackers are port
scanning the network, they don't usually do ICMP scans first. Its just
a waste of time.
>/sbin/ipfwadm -I -a accept -W $extif -P icmp -S $ISP_net/0 -D $extip/32
>/sbin/ipfwadm -I -a reject -W $extif -P icmp -S $universe/0 -D $extip/32
This is wrong. There are MANY types of ICMP packets out there:
--
Type Name Reference
---- ------------------------- ---------
0 Echo Reply [RFC792]
1 Unassigned [JBP]
2 Unassigned [JBP]
3 Destination Unreachable [RFC792]
4 Source Quench [RFC792]
5 Redirect [RFC792]
6 Alternate Host Address [JBP]
7 Unassigned [JBP]
8 Echo [RFC792]
9 Router Advertisement [RFC1256]
10 Router Selection [RFC1256]
11 Time Exceeded [RFC792]
12 Parameter Problem [RFC792]
13 Timestamp [RFC792]
14 Timestamp Reply [RFC792]
15 Information Request [RFC792]
16 Information Reply [RFC792]
17 Address Mask Request [RFC950]
18 Address Mask Reply [RFC950]
19 Reserved (for Security) [Solo]
20-29 Reserved (for Robustness Experiment) [ZSu]
30 Traceroute [RFC1393]
31 Datagram Conversion Error [RFC1475]
32 Mobile Host Redirect [David Johnson]
33 IPv6 Where-Are-You [Bill Simpson]
34 IPv6 I-Am-Here [Bill Simpson]
35 Mobile Registration Request [Bill Simpson]
36 Mobile Registration Reply [Bill Simpson]
37 Domain Name Request [Simpson]
38 Domain Name Reply [Simpson]
39 SKIP [Markson]
40 Photuris [Simpson]
41-255 Reserved [JBP]
--
Some can be filtered if you really want, others should NOT
be filtered. Again, I don't recommend it.
>(I know ipchains would be good to move to, but I am waiting for the Debian
>developers to make a 2.2 kernel that works on my machine).
What kind of machine?
--David
.----------------------------------------------------------------------------.
| David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] |
!---- ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.