This is for suggestions and feature requests you may have for future releases

Moderators: slax, siamer

Re: Firestarter Firewall

Postby slax » Fri Oct 08, 2010 8:06 am

Noted :)
slax
User avatar
Site Admin
Site Admin
 
Posts: 724
Joined: Wed Aug 18, 2010 2:55 pm
Location: ...somewhere out in space...

Re: No Firewall OOTB ( was Re: Firestarter Firewall)

Postby Digital_Resistance » Fri Oct 15, 2010 12:20 am

lightning slinger wrote:I meant 'any linux distro with firewall enabled' should show "stealth" even on dial-up as opposed to "closed".


Okay, thanks for clarifying.

Remembering that Shorewall is merely a script to configure the iptables around the options selected by the user.


I noticed that both iptables as well as ip6tables are listed as being "stopped" under "Services and daemons" in the Control Center-- despite my having installed Shorewall and activated the Firewall. (and all ports but 113 scanning as "stealth")

Does this make sense?

sarcastic bastard wrote:Gnome-PPP is indeed included, [in the GNOME Zen Mini edition]


Thank you.

Would anyone happen to know about the E-17 edition?

(It seems that the only other edition that comes with a dial-up GUI is the KDE version, which includes KPPP; A post made to the main PCLOS forum in April says the LXDE edition does not have one and I tried the Xfce edition in July and found no dial-up GUI in it either. It really would be nice if this info were to be listed somewhere. That way people with only dial-up could know whether a given edition or release has a dial-up GUI or not, before going to the trouble of purchasing a CD or bothering a friend with broadband.)

I think consideration should def be given to Firewall functionality "out of the box" in the next releases.


Especially considering how little space Shorewall, a 377k download, would take up on the ISO.

slax wrote:Noted :)


Appreciated. Thank you.
Digital_Resistance
Jr. Member
Jr. Member
 
Posts: 44
Joined: Mon Aug 16, 2010 12:44 am
Location: U.S.A.

Shorewall is Now Included!

Postby Digital_Resistance » Sun Mar 20, 2011 7:11 pm

I have finally tried PCLOS Gnome 2010.12 and was happy to see that Shorewall has indeed been added to the ISO, making it possible to activate the firewall "1-2-3" without downloading or updating anything. (as it already was in the KDE edition).

Thanks a lot devs!
Digital_Resistance
Jr. Member
Jr. Member
 
Posts: 44
Joined: Mon Aug 16, 2010 12:44 am
Location: U.S.A.

Re: Firestarter Firewall

Postby lightning slinger » Tue Mar 22, 2011 3:02 am

I noticed that both iptables as well as ip6tables are listed as being "stopped" under "Services and daemons" in the Control Center-- despite my having installed Shorewall and activated the Firewall. (and all ports but 113 scanning as "stealth")

Easiest way to 'stealth' the Authorization Port 113 is to 'comment out' (add #) to the line
Code: Select all
PARAM -  -  tcp 113
to become
Code: Select all
#PARAM -  -  tcp 113
in
Code: Select all
/usr/share/shorewall/macro.Auth
Asus KV8-X SE - Athlon 64 3200+ 2.0Ghz - 2GB DDR400 - Gnome 2010.07
Asus P4PE - Pentium 4 HT 3.06Ghz -2GB DDR333 - PCLOS Phoenix 2011.07
lightning slinger
User avatar
Full Member
Full Member
 
Posts: 171
Joined: Sat Aug 14, 2010 9:18 am
Location: UK

Re: Firestarter Firewall

Postby JNibski » Tue Mar 22, 2011 12:00 pm

...For stealthing #113 :

/usr/share/shorewall/macro.Auth


I have the same scenario in LXDE but it won't let me "overwrite" it.... :?:

JN.
EXPERIENCE is something you don’t get - until just after you need it.
JNibski
User avatar
Sr. Member
Sr. Member
 
Posts: 209
Joined: Sat May 16, 2009 3:02 pm

Re: Firestarter Firewall

Postby lightning slinger » Tue Mar 22, 2011 1:36 pm

JNibski wrote:...For stealthing #113 :

/usr/share/shorewall/macro.Auth


I have the same scenario in LXDE but it won't let me "overwrite" it.... :?:

JN.

It should do so in root, at least it does so in Gnome!

There is the other way to stealth #113

add the following line
Code: Select all
DROP net fw tcp 113
in
Code: Select all
/etc/shorewall/rules

EDIT: For those who don't know don't forget to reboot in both cases for this to become effective!
Last edited by lightning slinger on Tue Mar 22, 2011 1:51 pm, edited 2 times in total.
Asus KV8-X SE - Athlon 64 3200+ 2.0Ghz - 2GB DDR400 - Gnome 2010.07
Asus P4PE - Pentium 4 HT 3.06Ghz -2GB DDR333 - PCLOS Phoenix 2011.07
lightning slinger
User avatar
Full Member
Full Member
 
Posts: 171
Joined: Sat Aug 14, 2010 9:18 am
Location: UK

Re: Firestarter Firewall

Postby JNibski » Tue Mar 22, 2011 1:44 pm

Thanks LS ! The KEY was to do it in/as "ROOT".... :wink:

I have encountered clients with this #113 issue more than once, and now I have Answers... 8)

Thank you for the tips and rapid reply! Image

JN
EXPERIENCE is something you don’t get - until just after you need it.
JNibski
User avatar
Sr. Member
Sr. Member
 
Posts: 209
Joined: Sat May 16, 2009 3:02 pm

Re: Firestarter Firewall

Postby lightning slinger » Tue Mar 22, 2011 2:15 pm

JNibski wrote:... The KEY was to do it in/as "ROOT".... :wink:

JN


Sorry for confusing you, I had thought you would have known to edit shorewall you would need to be root!!
Asus KV8-X SE - Athlon 64 3200+ 2.0Ghz - 2GB DDR400 - Gnome 2010.07
Asus P4PE - Pentium 4 HT 3.06Ghz -2GB DDR333 - PCLOS Phoenix 2011.07
lightning slinger
User avatar
Full Member
Full Member
 
Posts: 171
Joined: Sat Aug 14, 2010 9:18 am
Location: UK

Re: Firestarter Firewall

Postby JNibski » Tue Mar 22, 2011 3:33 pm

....Yes, normally, yes.....this is why i brought it to light.... :wink:
Sometimes with various distros - certain methodologies might not work...
Sometimes a LINUX command needs something else...
You have given 2 methods here that seem to be the ticket, and it is appreciated by us "novice" senior folk.

In LXDE= one can do this by goin to : >MENU>FILETOOLS>FileMGRsuperuser>PCmanFM....etc...

JN.
EXPERIENCE is something you don’t get - until just after you need it.
JNibski
User avatar
Sr. Member
Sr. Member
 
Posts: 209
Joined: Sat May 16, 2009 3:02 pm

Re: Firestarter Firewall

Postby lightning slinger » Wed Mar 23, 2011 1:48 am

"novice" senior folk.

Hi!! I'm in that category too!!! :)
Asus KV8-X SE - Athlon 64 3200+ 2.0Ghz - 2GB DDR400 - Gnome 2010.07
Asus P4PE - Pentium 4 HT 3.06Ghz -2GB DDR333 - PCLOS Phoenix 2011.07
lightning slinger
User avatar
Full Member
Full Member
 
Posts: 171
Joined: Sat Aug 14, 2010 9:18 am
Location: UK

Re: Firestarter Firewall

Postby don_crissti » Wed Mar 23, 2011 5:42 am

JNibski wrote:In LXDE= one can do this by goin to : >MENU>FILETOOLS>FileMGRsuperuser>PCmanFM....etc...


superuser means root :wink:
Gnome has a right-click menu entry: "open as admin"
Those who cling to life, die; those who defy death, live.
Uesugi Kenshin
don_crissti
User avatar
Hero Member
Hero Member
 
Posts: 2261
Joined: Thu Nov 15, 2007 2:16 pm

Re: Firestarter Firewall

Postby sarcastic_bastard » Wed Mar 23, 2011 7:36 am

If you can't do something as user, it's usually a hint you need to be root. :)
Remember this, the only stupid question is the one you don't ask.

"The thing about changing the world... is that once you do it, the world's all different."

Let's share our knowledge. Otherwise, what's the point?
sarcastic_bastard
User avatar
Hero Member
Hero Member
 
Posts: 1705
Joined: Thu Oct 25, 2007 9:08 am
Location: Western Australia

Previous
Forum Statistics

Who is online

Users browsing this forum: No registered users and 0 guests

Options

Return to Feature Requests and Suggestions

cron