Jump to content

Firewall & Security Questions [solved]


vixenk
 Share

Recommended Posts

I had lots of problems with jetico. I thought it would be really good, but every time I shut it down it never remembered the settings. Tried running on Win2K and XP, same results.

 

It did work OK when running, but was a pain losing all the settings and resetting it each time it was launched. Oh, and it never remembered when you clicked never tell me about this event again, either.

Link to comment
Share on other sites

Just wanted to mention that Mandriva has this nice GUI for an Interactive Firewall, where you can manage your blacklist and whitelist. It also tells you when a host is being put into Blacklist (because of portscanning for example).

 

It's a nice tool to work with. It also sits in your taskbar within the eth0 icon.

Oh, almost forgot to mention, the installation:

# urpmi mandi-ifw

Link to comment
Share on other sites

good!

 

For the record: you could probably have figured out that something was blocking Samba traffic on the other computer by looking at /var/log/samba/xxxx.log files. "xxxx" by default contains the IP address or hostname of the connecting PC.

 

It is almost always rewarding to check log files when something stops/isn't working.

 

Are all the system application log files located in the /var/log directory, or are they scattered through out the system? Just wondering. :)

 

My final tip off was when I tried pinging the other computer and it returned all the packets... I was pretty sure that if shorewall was blocking access, I wouldn't have received ping backs, since I had them disabled in the basic setup. Was I right in this assumption?

 

You could check the ZoneAlarm logs, and allow blocked events related to your SMB client... but since ZoneAlarm isn't (IMHO) a good firewall anymore, then well done...

For the record, Jetico is a fine personal firewall for windows, and it's still free of charge.

For some reason, I have never figured out how to do this in ZoneAlarm... it's a weird firewall to me, and seems to try so hard to babysit the end user that it lacks a lot of what you would normally expect out of a firewall. I did have it configured to place my computer's IP in the trusted network zone, but evidently this wasn't enough. :S I don't really think it's a good firewall any more, either... I and almost everyone I know that's used it has had to deal with it randomly blocking various trusted program's internet access.

 

I've never tried out Jetico... don't think I've ever heard of it either, for that matter, lol. I installed Outpost, since it's one of the firewalls I trusted under Windows and gives me complete information about blocked attempts + good control over its rules *I'm crazy about that, and really glad I know how to create custom rules in shorewall now :)*.

Link to comment
Share on other sites

Are all the system application log files located in the /var/log directory, or are they scattered through out the system? Just wondering. :)

I guess this should be true for logs related to the system functioning.

 

Concerning (un)returned pings, the linux firewall ("iptables" which may be setup via shorewall which you can setup in MCC :) ) can either REJECT or DROP packets. In the former case you get a bounce, in the latter you get silence in reply instead.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
 Share

×
×
  • Create New...