stason.org logo lotus


previous page: 21  What are some cheap packet screening tools?page up: Firewalls FAQnext page: 23  Implementation (filtering rules for a kernel-based packet screen)

22 What are some reasonable filtering rules for a kernel-based packet screen?

 Books
 TULARC
















Description

This article is from the Firewalls FAQ, by Matt Curtin cmcurtin@interhack.net and Marcus J. Ranum mjr@nfr.com with numerous contributions by others.

22 What are some reasonable filtering rules for a kernel-based packet screen?

This example is written specifically for ipfwadm on Linux, but the
principles (and even much of the syntax) applies for other kernel interfaces
for packet screening on ``open source'' Unix systems.

There are four basic categories covered by the ipfwadm rules:

-A
Packet Accounting
-I
Input firewall
-O
Output firewall
-F
Forwarding firewall

ipfwadm also has masquerading (-M) capabilities. For more information on
switches and options, see the ipfwadm man page.

 

Continue to:


Share and Enjoy

Bookmark this story so others can enjoy it:
  • digg
  • Reddit
  • del.icio.us
  • Furl
  • Wists

Tags

security, Internet, firewalls, ssl, port, protection, application layer, proxy server, packet screening, filtering rules, viruses, terms







TOP
previous page: 21  What are some cheap packet screening tools?page up: Firewalls FAQnext page: 23  Implementation (filtering rules for a kernel-based packet screen)