Firewalls
Moderators: THE JEW (RaVeN), Ghost [PX]
- Ghost [PX]
- Posts: 3392
- Joined: Sun Mar 23, 2003 2:36 am
- Location: The smallest room in existence
- Contact:
Firewalls
Be thankful that we dont live in the US. Because a few congress men are getting all uppity, using a firewall in certain states may become illegal. Whoever thought that protecting your data would be a crime.
http://www.freedom-to-tinker.com/archives/000336.html
http://www.freedom-to-tinker.com/archives/000336.html
Nature is bountiful where idiots are concerned
No, they arent breasts, they're personalities, because its ok to like a girl for her personalities
It takes a big man to cry, but it takes a bigger man to laugh at that man
No, they arent breasts, they're personalities, because its ok to like a girl for her personalities
It takes a big man to cry, but it takes a bigger man to laugh at that man
- [PX] Nebuchadnezzar
- Posts: 3438
- Joined: Sun Mar 23, 2003 12:14 pm
- Location: London, Ontario
- Contact:
The Article wrote: Most operating system products (including every version of Windows introduced in the last five years, and virtually all versions of Linux) would also apparently be banned, because they support connection sharing via NAT.
Yikes is right! that sucks huge ass. good thing it's only in the states for now...
- [Fallen]Thanatos
- Posts: 2195
- Joined: Sun Mar 23, 2003 10:39 am
- Location: CFB Trenton
- THE JEW (RaVeN)
- Posts: 12499
- Joined: Sun Mar 23, 2003 2:52 pm
- Location: Bethlehem ;)
- Contact:
- THE JEW (RaVeN)
- Posts: 12499
- Joined: Sun Mar 23, 2003 2:52 pm
- Location: Bethlehem ;)
- Contact:
- THE JEW (RaVeN)
- Posts: 12499
- Joined: Sun Mar 23, 2003 2:52 pm
- Location: Bethlehem ;)
- Contact:
Re: Firewalls
A Linux open source firewall that is also a spam filter, virus scanner, VPN, spyware blocker and even more features if you pay (yes, those are the free features)
http://www.untangle.com/
Untangle
http://www.untangle.com/
Untangle
******* /=========\
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
- [Fallen]Thumperup
- Posts: 2630
- Joined: Sun Mar 23, 2003 9:05 am
- Location: Woodstock, Ontario
- Contact:
Re: Firewalls
That untangle looks really cool. I wonder how well it really works
- [Fallen]Thumperup
- Posts: 2630
- Joined: Sun Mar 23, 2003 9:05 am
- Location: Woodstock, Ontario
- Contact:
Re: Firewalls
i'm running through a untangle server right now RUNS awesome I think I might use it for Gamer's Edge.
I was looking for a simple easy to setup second router I think you just helped me find it Jew
I was looking for a simple easy to setup second router I think you just helped me find it Jew
- THE JEW (RaVeN)
- Posts: 12499
- Joined: Sun Mar 23, 2003 2:52 pm
- Location: Bethlehem ;)
- Contact:
Re: Firewalls
Sweet. What hardware you running it on?
******* /=========\
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
- [Fallen]Thumperup
- Posts: 2630
- Joined: Sun Mar 23, 2003 9:05 am
- Location: Woodstock, Ontario
- Contact:
Re: Firewalls
old hardware I had laying around..... 1ghz proc, 512MB ram 80Gig Hdd. Runs great a bit slow on changing settings but no real complaints.
- [Fallen]Thumperup
- Posts: 2630
- Joined: Sun Mar 23, 2003 9:05 am
- Location: Woodstock, Ontario
- Contact:
Re: Firewalls
now using untangle at home from now on
So i've setup a DMZ here next step maybe getting website back up
So i've setup a DMZ here next step maybe getting website back up
- THE JEW (RaVeN)
- Posts: 12499
- Joined: Sun Mar 23, 2003 2:52 pm
- Location: Bethlehem ;)
- Contact:
Re: Firewalls
Does Untangle really need a HD that big? What apps have you installed?
pfSense
A FreeBSD-based router and firewall:
http://doc.pfsense.org/index.php/Main_Page
Documentation:
http://doc.pfsense.org/index.php/Main_Page
Tutorials (says you need Firefox but work here on Dempsey's version of Opera):
http://doc.pfsense.org/index.php/Tutorials
Installing ports to pfSense so that you can access any FreeBSD package:
http://doc.pfsense.org/index.php/Instal ... D_Packages
All packages known to work with pfSense as of late 2006 (unlikely that all of them do now ie. ClamAV):
http://files.pfsense.org/packages/All/
Problems with Packages?
Cannot install packages:
http://forum.pfsense.org/index.php/topic,7469.0.html
Cannot install, fails to fetch:
http://forum.pfsense.org/index.php/topic,8302.0.html
Question on antivirus leads to packages:
http://forum.pfsense.org/index.php?topic=8442.msg47627
Vnstat is a traffic logger:
http://humdi.net/vnstat/
Guide to install on pfSense using packages:
http://forum.pfsense.org/index.php/topic,8460.0.html
Snort is an IDS / IPS commonly used on these:
http://www.snort.org/
Snortinline is a slightly modified, slightly advanced version of it:
http://snort-inline.sourceforge.net/index.html
Snortinline tutorials:
http://www.openmaniak.com/inline_tutorial.php
Suricata which is another IPS / IDS
http://www.inliniac.net/blog/
spamd will help provide spam filtering:
http://www.openbsd.org/spamd/
pfSense
A FreeBSD-based router and firewall:
http://doc.pfsense.org/index.php/Main_Page
Documentation:
http://doc.pfsense.org/index.php/Main_Page
Tutorials (says you need Firefox but work here on Dempsey's version of Opera):
http://doc.pfsense.org/index.php/Tutorials
Installing ports to pfSense so that you can access any FreeBSD package:
http://doc.pfsense.org/index.php/Instal ... D_Packages
All packages known to work with pfSense as of late 2006 (unlikely that all of them do now ie. ClamAV):
http://files.pfsense.org/packages/All/
Problems with Packages?
Cannot install packages:
http://forum.pfsense.org/index.php/topic,7469.0.html
Cannot install, fails to fetch:
http://forum.pfsense.org/index.php/topic,8302.0.html
Question on antivirus leads to packages:
http://forum.pfsense.org/index.php?topic=8442.msg47627
Vnstat is a traffic logger:
http://humdi.net/vnstat/
Guide to install on pfSense using packages:
http://forum.pfsense.org/index.php/topic,8460.0.html
Snort is an IDS / IPS commonly used on these:
http://www.snort.org/
Snortinline is a slightly modified, slightly advanced version of it:
http://snort-inline.sourceforge.net/index.html
Snortinline tutorials:
http://www.openmaniak.com/inline_tutorial.php
Let's install Snort_Inline.
You must install the prerequisite tools to be able to compile Snort_Inline successfully.
SNORT_INLINE DOWNLOAD AND CONFIGURATION
Download Snort_Inline and uncompress it.Code: Select all
#tar -xvf snort_inline-2.4.5a.tar.gz
Create two directories, one to store the configuration files, the other one to store the Snort rules.Code: Select all
#mkdir /etc/snort_inline
#mkdir /etc/snort_inline/rules
Copy the Snort_Inline configuration files inside the /etc/snort_inline/ directory.Code: Select all
#cp snort_inline-2.4.5a/etc/* /etc/snort_inline/
Inside the /etc/snort_inline/snort_inline.conf file, look for the line beginning by "var RULE_PATH" and change it as below:Code: Select all
var RULE_PATH /etc/snort_inline/rules
Copy two files inside our new /etc/snort_inline/rules directory:
- classification.config: defines URLs for the references found in the rules.
- reference.config: includes information for prioritizing rules.Code: Select all
#cp snort_inline-2.4.5a/etc/classification.config /etc/snort_inline/rules/
#cp snort_inline-2.4.5a/etc/reference.config /etc/snort_inline/rules/
Create a log directory:Code: Select all
#mkdir /var/log/snort_inline
MYSQL SETTINGS
Get information about the MySQL database.
Add a password for the MySQL root user:Code: Select all
#mysqladmin -u root password new_root_password
Create the MySQL database and tables in order to receive the Snort logs:Code: Select all
#mysql -u root -p
>create database snort;
Since it is dangerous to access the database with the root user, we need to create a user who has permissions on the snort database only:Code: Select all
>grant all on snort.* to snortuser@localhost identified by 'snortpassword';
Reload the MySQL privileges:Code: Select all
>flush privileges;
>exit;
Now we have to create the tables inside the snort database:
By chance the tables are already created, we just have to find and import them into the SQL server:Code: Select all
#mysql -u root -p snort < snort_inline-2.4.5a/schemas/create_mysql
Configure the MySQL database settings:
Open the snort_inline.conf file:Code: Select all
#vi /etc/snort_inline/snort_inline.conf
After the line with "output alert_fast: snort_inline-fast", add:Code: Select all
output database: log, mysql, user=snortuser password=snortpassword dbname=snort host=localhost
SNORT_INLINE COMPILATION AND INSTALLATION
You need first to use commands to check the dependencies and prepare the tool to be compiled for MySQL.Code: Select all
#cd snort_inline-2.4.5a
#./configure --with-mysql
If you installed all the dependencies correctly, the "configure" command must end without any error!
If you have an error message, see the bottom of the page.
Then we compile and install Snort_Inline.Code: Select all
#make
#checkinstall
See the CheckInstall page for more details about this command.
Below the output on our test system:
checkinstall 1.6.0, Copyright 2002 Felipe Eduardo Sanchez Diaz Duran
This software is released under the GNU GPL.
The package documentation directory ./doc-pak does not exist.
Should I create a default set of package docs? [y]: y
Preparing package documentation...OK
Please write a description for the package.
End your description with an empty line or EOF.
>>
*****************************************
**** Debian package creation selected ***
*****************************************
*** Warning: The package name "snort_inline-2.4.5a" contains underscores.
*** Warning: dpkg might not like that so I changed
*** Warning: them to dashes.
This package will be built according to these values:
0 - Maintainer: [ root@ubuntu ]
1 - Summary: [ Package created with checkinstall 1.6.0 ]
2 - Name: [ snort-inline-2.4.5a ]
3 - Version: [ BETA1 ]
4 - Release: [ 1 ]
5 - License: [ GPL ]
6 - Group: [ checkinstall ]
7 - Architecture: [ i386 ]
8 - Source location: [ snort_inline-2.6.1.2-BETA1 ]
9 - Alternate source location: [ ]
10 - Requires: [ ]
Error messages you can get after the "./configure" command:
You don't have the build-essential metapackage:
checking for a BSD-compatible install... /usr/bin/install -c
checking whether build environment is sane... yes
checking for gawk... no
checking for mawk... mawk
checking whether make sets $(MAKE)... no
checking whether to enable maintainer-specific portions of Makefiles... no
checking for style of include used by make... none
checking for gcc... no
checking for cc... no
checking for cc... no
checking for cl... no
configure: error: no acceptable C compiler found in $PATH
See `config.log' for more details.
You don't have the libnet package:
ERROR! Libpcap library/headers not found, go get it from
http://www.tcpdump.org
or use the --with-libpcap-* options, if you have it installed
in unusual place
You don't have the libpcre3-dev package:
ERROR! Libpcre header not found, go get it from
http://www.pcre.org
You don't have the iptables-dev package:
checking for libipq.h... no
configure: error: libipq.h not found ...
You don't have the libmysqlclient12-dev package:
ERROR: unable to find mysql headers (mysql.h)
checked in the following places
/usr/include
/usr/include/mysql
/usr/local/include
/usr/local/include/mysql
You don't have the libdnet library:
ERROR! Libdnet header not found, go get it from
http://libdnet.sourceforge.net or use the --with-dnet-*
options, if you have it installed in an unusual place
Suricata which is another IPS / IDS
http://www.inliniac.net/blog/
spamd will help provide spam filtering:
http://www.openbsd.org/spamd/
******* /=========\
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
- [Fallen]Thumperup
- Posts: 2630
- Joined: Sun Mar 23, 2003 9:05 am
- Location: Woodstock, Ontario
- Contact:
Re: Firewalls
no it does not but it was one of the smallest I had laying around 
- THE JEW (RaVeN)
- Posts: 12499
- Joined: Sun Mar 23, 2003 2:52 pm
- Location: Bethlehem ;)
- Contact:
Re: Firewalls
What size is it and which of the apps have you installed? Thanks.
******* /=========\
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
****(_]/_____________\[_)
***** /(__)==JEW==(__)\
***** |=o__________o=|
***** |_|====---====|_|

¨˜”°º•[K]•º°”˜¨
- [Fallen]Thumperup
- Posts: 2630
- Joined: Sun Mar 23, 2003 9:05 am
- Location: Woodstock, Ontario
- Contact:
Re: Firewalls
Total Disk space: 78.71GB Free Space: 76.29GB
Spam Blocker
Phish Blocker
Spyware Blocker
Web Filter
Virus Blocker
Intrusion Prevention
Protocol Control
Firewall
Open VPN
Attack Blocker
Reports
Sooooo all the free ones lol I don't need wan balancer or wan fail over I only have 1 connection
Spam Blocker
Phish Blocker
Spyware Blocker
Web Filter
Virus Blocker
Intrusion Prevention
Protocol Control
Firewall
Open VPN
Attack Blocker
Reports
Sooooo all the free ones lol I don't need wan balancer or wan fail over I only have 1 connection

