RE: Which Firewall solutions

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



>>So come up with specific questions you don't understand, and we'll all 
>>take a crack at solving them.

Okay.. Here's another one.. Maybe this will need me to install a "Real"
firewall such as shorewall. (Downloaded but not looked into it yet)

I recently helped another colleague set up a file server. During the config
stages, I found that samba won't work because port 139 is blocked when I try
to connect from another PC. Works when connected as localhost. 

Upon checking, I found out that eth0(LAN) is listed as _not_trusted_
(redhat-config-security - known as Lokkit I think). And There are _no_
options for including samba ports. After putting eth0 as trusted, Everything
works right.

now, the thing here is I _do_ not want the LAN(eth0) to regard all traffic
as trusted. (I think this is a fair request) As of right now, I would only
like for ports 443(Https) 80(http) 22(SSH) 139(smb) to be open for business
and other ports would be closed to the world.

Is there any way to do this using the "default" RH9 programs? 

I know I can do it if I were to edit the iptables myself, but I'm not
confident in doing a good job. (I am reading up on the ip-tables tutorial)

<DAMN good quote from Rodolfo>
Plus, this is part of the Linux culture, and part of the Open Source 
culture. You will get TONS AND TONS of help right now, when you know 
nothing or next to nothing, and you'll get all this help for free. What 
makes it fair and reasonable is that you acquire the moral obligation to 
give as you were given: once you master a subject, make sure you spend some 
time helping others. Share whatever knowledge you have, remember where you 
came from, and help others learn too... that's how you pay back the help 
you were given.
</quote>

So.. Help me help others.... Pay it forward... :) (starting with me)



Cheers,                                                 .^.
Mun Heng, Ow                                            /V\
H/M Engineering                                       /(   )\
Western Digital M'sia                                  ^^-^^
DID : 03-7870 5168                          The Linux Advocate

        


-- 
Shrike-list mailing list
Shrike-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/shrike-list

[Index of Archives]     [Fedora Users]     [Centos Users]     [Kernel Development]     [Red Hat Install]     [Red Hat Watch]     [Red Hat Development]     [Red Hat Phoebe Beta]     [Yosemite Forum]     [Fedora Discussion]     [Gimp]     [Stuff]     [Yosemite News]

  Powered by Linux