Linux Firewall, etc.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, 4 Aug 2001, Peter Toneby wrote:
 > This sure makes sense.
 > You don't need extra software because the stuff that handles firewalls
 > in linux is built into the kernel (more or less, it could be
 > kernelmodules). What you need is to install linux and then find a good
 > documentation on the way your kernelversion handles firewalling. The
 > firewall stuff is called ipchains in Linux 2.2.x, and iptables in 2.4.x.
Wheile this is correct, you forget one important point.
For internet-sharing no software is neede either. This is because linxu
does something whihc they call ipmasquarading, but inf firewall terms is
known as NAT (netwwork address translation).

In short:
the network card connected to the dsl-modem has an anddress of say 1.2.3.4
Your internal network has addressses in the range of 192.168.0.x where 0 <
x < 255 (0 and 55 are network and broadcast address respectively).
Your 2nd card in the firewall-bo would have say 192.168.0.1 (this is an
unwritten default for gateways).

Now, under windows setup fixed addressing and give it say: 192.168.0.10 as
ip, 255.255.255.0 as netmask and 192.168.0.1 as gateway

Now yout telnet issue (be sure to close telnet for the outside world
though).
Login with telnet on the linux box, make sure screen and lynx are installed
start screen
Iwht ctrl+a c  you can create other screens, with ctrl+a p or n you can
shift between screens (or use 0-9 for the first 10 screens)
with ctrl+a d you can  detatch (all lynx versions you started will keep
running as long as the linux box keeps running).
Whe logging in later, do screen -r and yer back were you left off.

http://metalab.unc.edu/LDP/ has an exeant HOWTO on ipchains.

 > There are programs available to simplify the creation of firewall-rules,
 > but I think most are made for X, and so are hard to use.
 > 
 > /Peter, who just lost his firewall due to faulty cache in the CPU
 > -- 
 > Alpha Test Version:  Too buggy to be released to the paying public. 
 > Beta Test Version:  Still too buggy to be released. 
 > Release Version:  Alternate pronunciation of "Beta Test Version". 
 > 
 > 
 > 
 > _______________________________________________
 > 
 > Blinux-list@redhat.com
 > https://listman.redhat.com/mailman/listinfo/blinux-list
 > 

slainte mhaith (good health), slainte (cheers)
Uisce Beatha (water of live/health)
-----------
Andor Demarteau                 E-mail: ademarte@students.cs.uu.nl
student computer science        www: http://www.students.cs.uu.nl/~ademarte/
Utrecht University              irc: see webpage for details
-----------
Believe in yourself, know what you want, and make it happen!





[Index of Archives]     [Linux Speakup]     [Fedora]     [Linux Kernel]     [Yosemite News]     [Big List of Linux Books]