PDA

View Full Version : firewall rules help


iceni60
November 25th, 2005, 09:59 PM
i just set up my Ubuntu firewall. could you tell me if you think these rules look OK, i wish they gave the icmp numbers instead of things like pong lol i'm trying to stop inbound icmp 8. does this look secure to you? thanks

Kerodo
November 25th, 2005, 11:03 PM
Well, assuming they're talking about incoming, then it looks alright. You have Ping unchecked, and that's ICMP type 8, so you're not allowing it. Again, I am assuming they mean inbound. Not sure if you can Ping others outbound. But that would be my guess on things too.

iceni60
November 25th, 2005, 11:11 PM
thanks, i just went to Shields Up and with these settings i passed. when i changed ping and pong around i failed, saying i responded to pings. so i think it's correct. thanks for the help :) if anyone sees something i should change can you let me know? thanks.

thanks, CrazyM for editing the picture, i had alook in Gimp but didn't know what to do.

CrazyM
November 25th, 2005, 11:14 PM
So it does not allow configuration for separate inbound and outbound ICMP rules?

Regards,

CrazyM

iceni60
November 25th, 2005, 11:17 PM
-{ Quote: "So it does not allow configuration for separate inbound and outbound ICMP rules?

Regards,

CrazyM" }-
only for ping and pong lol by the look of things. i was thinking of getting something else as this is a frontend for iptables, but i find it difficult to in/uninstall programs so i'll leave it for abit.

Hyperion
November 26th, 2005, 04:19 AM
I ve only small experience with Linux,but Firestarter is the best GUI for Iptables i found.Tried Guarddog too,but didn't like it much.So,unless you can configure Iptables directly,i think you should stick to Firestarter.It's easy and works.

iceni60
November 26th, 2005, 02:06 PM
-{ Quote: "I ve only small experience with Linux,but Firestarter is the best GUI for Iptables i found.Tried Guarddog too,but didn't like it much.So,unless you can configure Iptables directly,i think you should stick to Firestarter.It's easy and works." }-
i'd like a frontend. i just found this - Gtk-IPTables it looks perfect.
http://gtk-iptables.sourceforge.net/screenshots.html
http://gtk-iptables.sourceforge.net/