<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>EssayBoard &#187; firewall</title>
	<atom:link href="http://essayboard.com/tag/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://essayboard.com</link>
	<description>All about technology!</description>
	<lastBuildDate>Sat, 11 Feb 2012 21:14:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='essayboard.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/e1f03ef6e553242f1ca50ae9b6e394c0?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>EssayBoard &#187; firewall</title>
		<link>http://essayboard.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://essayboard.com/osd.xml" title="EssayBoard" />
	<atom:link rel='hub' href='http://essayboard.com/?pushpress=hub'/>
		<item>
		<title>How To Enable Dynamic Firewall On Fedora 16</title>
		<link>http://essayboard.com/2011/11/11/how-to-enable-dynamic-firewall-on-fedora-16/</link>
		<comments>http://essayboard.com/2011/11/11/how-to-enable-dynamic-firewall-on-fedora-16/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 05:48:45 +0000</pubDate>
		<dc:creator>Vinh Nguyen</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[dynamic firewall]]></category>
		<category><![CDATA[Fedora]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Gnome]]></category>
		<category><![CDATA[Iptables]]></category>
		<category><![CDATA[Linux distribution]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://essayboard.com/?p=8315</guid>
		<description><![CDATA[The developers behind a Linux distribution known as Fedora have been working on a new type of firewall system known as Dynamic Firewall.  Since Fedora 15, users could install Dynamic Firewall.  It&#8217;s kind of a disappointment for me to see the latest Fedora 16 isn&#8217;t yet shipped with the Dynamic Firewall.  Nonetheless, as how Fedora&#8230;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=8315&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 277px"><a href="http://commons.wikipedia.org/wiki/File:Fedora_logo.svg"><img class="zemanta-img-inserted zemanta-img-configured" title="The official symbol of the Linux distribution ..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/3/3f/Fedora_logo.svg/267px-Fedora_logo.svg.png" alt="The official symbol of the Linux distribution ..." width="267" height="267" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
<p>The developers behind a <a class="zem_slink" title="Linux distribution" href="http://en.wikipedia.org/wiki/Linux_distribution" rel="wikipedia">Linux distribution</a> known as Fedora have been working on a new type of firewall system known as Dynamic Firewall.  Since Fedora 15, users could install Dynamic Firewall.  It&#8217;s kind of a disappointment for me to see the latest Fedora 16 isn&#8217;t yet shipped with the Dynamic Firewall.  Nonetheless, as how Fedora 15 was, users can still install Dynamic Firewall with Fedora 16.</p>
<p>For your information, Fedora 16 isn&#8217;t enabling any firewall by default.  Yes, Fedora 16 is still shipping with the traditional <a class="zem_slink" title="Iptables" href="http://www.netfilter.org/" rel="homepage">IPTables</a> firewall system.  The question is, why users want to use Fedora&#8217;s Dynamic Firewall over the traditional IPTables type of firewall?  It&#8217;s because Dynamic Firewall is somewhat smarter.</p>
<p>I&#8217;d made a video which shows you how to disable the traditional firewall, enable the Dynamic Firewall, and how to revert back to the traditional firewall from Dynamic Firewall.  The video also points out why and how Dynamic Firewall is smarter than the traditional firewall (i.e., IPTables).  You can check out the video right after the break.</p>
<p><span style="text-align:center; display: block;"><a href="http://essayboard.com/2011/11/11/how-to-enable-dynamic-firewall-on-fedora-16/"><img src="http://img.youtube.com/vi/N7cxbmGpEJE/2.jpg" alt="" /></a></span></p>
<h6 class="zemanta-related-title" style="font-size:1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.h-online.com/open/news/item/Fedora-16-released-1375215.html">Fedora 16 released</a> (h-online.com)</li>
<li class="zemanta-article-ul-li"><a href="http://essayboard.com/2011/11/10/disabling-enabling-starting-stopping-and-restarting-services-on-fedora-16/">Disabling, Enabling, Starting, Stopping, And Restarting Services On Fedora 16</a> (essayboard.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.h-online.com/open/news/item/Fedora-launches-community-knowledge-base-1376531.html">Fedora launches community knowledge base</a> (h-online.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2011/10/12/fedora_17_beefy_miracle/">Users decide Fedora 17 will be &#8216;Beefy Miracle&#8217;</a> (go.theregister.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/243189/six_good_reasons_to_try_fedora_16.html">Six Good Reasons to Try Fedora 16</a> (pcworld.com)</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/essayboard.wordpress.com/8315/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/essayboard.wordpress.com/8315/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/essayboard.wordpress.com/8315/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/essayboard.wordpress.com/8315/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/essayboard.wordpress.com/8315/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/essayboard.wordpress.com/8315/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/essayboard.wordpress.com/8315/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/essayboard.wordpress.com/8315/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/essayboard.wordpress.com/8315/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/essayboard.wordpress.com/8315/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/essayboard.wordpress.com/8315/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/essayboard.wordpress.com/8315/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/essayboard.wordpress.com/8315/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/essayboard.wordpress.com/8315/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=8315&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://essayboard.com/2011/11/11/how-to-enable-dynamic-firewall-on-fedora-16/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8e5039f4535d34121a1108ca8ad38d90?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">argh2xxx</media:title>
		</media:content>

		<media:content url="http://upload.wikimedia.org/wikipedia/commons/thumb/3/3f/Fedora_logo.svg/267px-Fedora_logo.svg.png" medium="image">
			<media:title type="html">The official symbol of the Linux distribution ...</media:title>
		</media:content>
	</item>
		<item>
		<title>Product Review:  Norton Internet Security 2012 (Video)</title>
		<link>http://essayboard.com/2011/10/12/product-review-norton-internet-security-2012-video/</link>
		<comments>http://essayboard.com/2011/10/12/product-review-norton-internet-security-2012-video/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 23:16:35 +0000</pubDate>
		<dc:creator>Vinh Nguyen</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Norton]]></category>
		<category><![CDATA[Norton Internet Security 2012]]></category>
		<category><![CDATA[product review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://essayboard.com/?p=7828</guid>
		<description><![CDATA[It&#8217;s this time of the year that new computer security products make themselves known.  It&#8217;s this time of the year that I like to do product reviews on various computer security products.  Well, within this post, I like to post a video that I had created for the purpose of reviewing Symantec&#8217;s Norton Internet Security&#8230;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=7828&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s this time of the year that new computer security products make themselves known.  It&#8217;s this time of the year that I like to do product reviews on various computer security products.  Well, within this post, I like to post a video that I had created for the purpose of reviewing Symantec&#8217;s Norton Internet Security 2012.  So, I hope you&#8217;ll enjoy the &#8220;Product Review:  Norton Internet Security 2012&#8243; video right after the break.</p>
<p><span style="text-align:center; display: block;"><a href="http://essayboard.com/2011/10/12/product-review-norton-internet-security-2012-video/"><img src="http://img.youtube.com/vi/75WUy1b-euc/2.jpg" alt="" /></a></span></p>
<p>Questions:</p>
<ol>
<li>Do you think Norton Internet Security 2011 was a good product?</li>
<li>Do you think that you&#8217;re going to try out Norton Internet Security 2012?</li>
</ol>
<p>Please leave your answers in the comment section below this post.  Thank you!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/essayboard.wordpress.com/7828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/essayboard.wordpress.com/7828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/essayboard.wordpress.com/7828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/essayboard.wordpress.com/7828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/essayboard.wordpress.com/7828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/essayboard.wordpress.com/7828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/essayboard.wordpress.com/7828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/essayboard.wordpress.com/7828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/essayboard.wordpress.com/7828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/essayboard.wordpress.com/7828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/essayboard.wordpress.com/7828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/essayboard.wordpress.com/7828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/essayboard.wordpress.com/7828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/essayboard.wordpress.com/7828/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=7828&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://essayboard.com/2011/10/12/product-review-norton-internet-security-2012-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8e5039f4535d34121a1108ca8ad38d90?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">argh2xxx</media:title>
		</media:content>
	</item>
		<item>
		<title>IPV6 Won&#8217;t Use NAT And Other Private Features, Requiring Firewall To Protect IPV6 IP Addresses From Prying Eyes</title>
		<link>http://essayboard.com/2011/08/10/ipv6-wont-use-nat-and-other-private-features-requiring-firewall-to-protect-ipv6-ip-addresses-from-prying-eyes/</link>
		<comments>http://essayboard.com/2011/08/10/ipv6-wont-use-nat-and-other-private-features-requiring-firewall-to-protect-ipv6-ip-addresses-from-prying-eyes/#comments</comments>
		<pubDate>Wed, 10 Aug 2011 16:58:09 +0000</pubDate>
		<dc:creator>Vinh Nguyen</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://essayboard.com/?p=7231</guid>
		<description><![CDATA[IPV6 was all the rage couple months ago, but we haven&#8217;t heard much about it now.  Nonetheless, don&#8217;t think for a second that IPV6 won&#8217;t come!  I think it will come slowly, but it will be here eventually.  Noticeably, people won&#8217;t be able to use IPV6 if their ISPs aren&#8217;t yet ready! Fortunately, responsible ISPs&#8230;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=7231&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>IPV6 was all the rage couple months ago, but we haven&#8217;t heard much about it now.  Nonetheless, don&#8217;t think for a second that IPV6 won&#8217;t come!  I think it will come slowly, but it will be here eventually.  Noticeably, people won&#8217;t be able to use IPV6 if their ISPs aren&#8217;t yet ready!</p>
<p>Fortunately, responsible ISPs will definitely roll out newer firmwares to update customers&#8217; routers/gateways so IPV6 will be supported.  In the worse case scenario, customers may have to demand for newer routers/gateways from their ISPs before IPV6 will be enabled in their home/office networks.</p>
<p>Not only the routers/gateways have to be IPV6 enabled, each user&#8217;s computer must be configured to support IPV6.  I&#8217;d read somewhere that IPV6 will expose all internal devices to the Internet, because IPV6&#8242;s IP distribution is more tied to the world than not (i.e., there are countless more IP addresses from IPV6 than IPV4).  To put this in a clearer context for some people, IPV6 forgoes NAT and other private features.  NAT stands for Network Address Translation where it acts as a barrier and correlation between public IP addresses and private network IP addresses (e.g., 192.168.x.x).  This is why people definitely have to learn how to enabling firewall for IPV6 so their devices&#8217; IP addresses won&#8217;t be exposed.</p>
<p>Customers who are relying on premium security suites from well known brands might not have to do much for them to have a functioning IPV6 firewall, because newer updates to their security suite software will come with active IPV6 firewall, I guess.  Linux users on the other hand might have to get down and dirty.  I&#8217;m not sure if Linux users can clone IPV4&#8242;s iptables to protect their IPV6&#8242;s network.  The user space application program for IPV6&#8242;s Linux kernel firewall has to be ip6tables.  I&#8217;m definitely going to look more into how to enable firewall for IPV6 in Linux.</p>
<p>Update:  Apparently, I don&#8217;t think it&#8217;s hard to enable IPV6 firewall in certain Linux distributions such as Ubuntu 11.04!  As long Uncomplicated Firewall is enabled in such Linux distributions and the users know how to use UFW, then they can easily configure UFW to protect their devices on IPV6 network.  UFW has a graphical version which is known as Gufw, and so it should be a lot easier to use the Gufw than the command line version UFW.  For your information UFW/Gufw is very easy to use, because I&#8217;ve tested UFW/Gufw on Ubuntu 11.04.  I&#8217;ve found UFW/Gufw to be simple and more intuitive than most Linux&#8217;s frontend programs for iptables/ip6tables.</p>
<p><a href="http://essayboard.files.wordpress.com/2011/08/ufw-ipv6-enabled-pix1.png"><img class="alignnone size-medium wp-image-7238" title="ufw-ipv6-enabled-pix1" src="http://essayboard.files.wordpress.com/2011/08/ufw-ipv6-enabled-pix1.png?w=300&#038;h=134" alt="" width="300" height="134" /></a></p>
<p>Click <a title="Uncomplicated Firewall" href="https://wiki.ubuntu.com/UncomplicatedFirewall" target="_blank">here</a> to go to the screenshot&#8217;s source!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/essayboard.wordpress.com/7231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/essayboard.wordpress.com/7231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/essayboard.wordpress.com/7231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/essayboard.wordpress.com/7231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/essayboard.wordpress.com/7231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/essayboard.wordpress.com/7231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/essayboard.wordpress.com/7231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/essayboard.wordpress.com/7231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/essayboard.wordpress.com/7231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/essayboard.wordpress.com/7231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/essayboard.wordpress.com/7231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/essayboard.wordpress.com/7231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/essayboard.wordpress.com/7231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/essayboard.wordpress.com/7231/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=7231&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://essayboard.com/2011/08/10/ipv6-wont-use-nat-and-other-private-features-requiring-firewall-to-protect-ipv6-ip-addresses-from-prying-eyes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8e5039f4535d34121a1108ca8ad38d90?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">argh2xxx</media:title>
		</media:content>

		<media:content url="http://essayboard.files.wordpress.com/2011/08/ufw-ipv6-enabled-pix1.png?w=300" medium="image">
			<media:title type="html">ufw-ipv6-enabled-pix1</media:title>
		</media:content>
	</item>
		<item>
		<title>Fedora 15 Will Ditch IP Tables And Adopt Dynamic Firewall</title>
		<link>http://essayboard.com/2011/05/22/fedora-15-will-ditch-ip-tables-and-adopt-dynamic-firewall/</link>
		<comments>http://essayboard.com/2011/05/22/fedora-15-will-ditch-ip-tables-and-adopt-dynamic-firewall/#comments</comments>
		<pubDate>Sun, 22 May 2011 07:01:53 +0000</pubDate>
		<dc:creator>Vinh Nguyen</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[dynamic firewall]]></category>
		<category><![CDATA[Fedora]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ip tables]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://essayboard.com/?p=5647</guid>
		<description><![CDATA[According to Esecurityplanet.com, Fedora 15 will use a different kind of firewall technology and ditch IP tables.  They coin this new firewall technology as dynamic firewall.  This new firewall technology is really new to me since I&#8217;ve not yet thoroughly tested out Fedora 15, but from the hearsay it seems that this new firewall technology&#8230;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=5647&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>According to Esecurityplanet.com, Fedora 15 will use a different kind of firewall technology and ditch IP tables.  They coin this new firewall technology as dynamic firewall.  This new firewall technology is really new to me since I&#8217;ve not yet thoroughly tested out Fedora 15, but from the hearsay it seems that this new firewall technology is an improvement over IP tables by allowing users to be more interactive with their firewall.  How?  Let say if a user has an app on their Fedora system and an app wants to make an outgoing connection, this dynamic firewall will probably allow users to make a choice to either allowing an app to make an outgoing connection or not, but the change will be permanent; in the case of another rule with higher authority, then I guess the app will be able to make an outgoing connection for certain amount of a duration of time before the dynamic firewall will prevent such app to make an outgoing connection again.</p>
<p>Come to think of it, dynamic firewall sounds like a firewall that Windows users are familiar with such as Norton 2011&#8242;s firewall.  To my knowledge, Norton 2011&#8242;s firewall asks users to make decisions base on app by app basis and also base on connection by connection basis.  Anyhow, dynamic firewall is still too new to me, and so I don&#8217;t even know what I&#8217;m writing on this blog post is having any merit on facts at all.  In fact, I fear what I&#8217;m writing here will all be gibberish, because one needs to test out the product first before one can truly know the merits of the product.  Nonetheless, the news is that Fedora 15 won&#8217;t use IP tables.</p>
<p>Personally, I think even the firewall means well when it presents to the users with several choices in term of allowing an outgoing connection or incoming connection, it&#8217;s still a bad thing for users.  Why?  Some computer users may not know enough about their systems, therefore they may choose the wrong choices.  Choosing the wrong choices can render their systems less secure.  An example would be a user who was presented with choices of allowing or not allowing an incoming connection of an app on his or her system, but for some strange reasons the user didn&#8217;t know enough about this specific app and didn&#8217;t look on the Internet for additional information on such app and yet he or she had allowed an incoming connection.  In the end, a user&#8217;s system was hacked, because it was compromised by a hacker who had deliberately tricked the user to download an app earlier.  This is only one example among many, and yet it has already told us that even with the best firewall, it&#8217;s still depending on a user&#8217;s decisions/actions most.</p>
<p>Perhaps, a firewall should present users will less choices, and it would be better for users in term of securing their systems.  Even better, allowing expert users to use advance mode, because veteran computer users can make better choices than novice computer users in term of allowing certain connections to be interacted with their systems.  Advance mode of such firewall should present to veteran computer users with more choices so they can make sound decisions.  Basic mode of such firewall should present less choices so novice computer users won&#8217;t have to choose the wrong choices, consequently improving the overall security of the computers and networks.</p>
<p>What you think about dynamic firewall of Fedora 15?  Do you think that it&#8217;s better for a firewall to present users with more choices in term of allowing users to make decisions for incoming and outgoing connections?  Do you think that dynamic firewall is an improvement over IP tables?</p>
<p>Source:  <a title="Fedora 15 Boosts Linux Security" href="http://www.esecurityplanet.com/news/article.php/3934151/Fedora-15-Boosts-Linux-Security.htm" target="_blank">http://www.esecurityplanet.com/news/article.php/3934151/Fedora-15-Boosts-Linux-Security.htm</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/essayboard.wordpress.com/5647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/essayboard.wordpress.com/5647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/essayboard.wordpress.com/5647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/essayboard.wordpress.com/5647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/essayboard.wordpress.com/5647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/essayboard.wordpress.com/5647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/essayboard.wordpress.com/5647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/essayboard.wordpress.com/5647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/essayboard.wordpress.com/5647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/essayboard.wordpress.com/5647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/essayboard.wordpress.com/5647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/essayboard.wordpress.com/5647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/essayboard.wordpress.com/5647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/essayboard.wordpress.com/5647/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=5647&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://essayboard.com/2011/05/22/fedora-15-will-ditch-ip-tables-and-adopt-dynamic-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8e5039f4535d34121a1108ca8ad38d90?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">argh2xxx</media:title>
		</media:content>
	</item>
		<item>
		<title>Introducing APF Firewall For Ubuntu, But You Can Use This On Many Other Linux Flavors</title>
		<link>http://essayboard.com/2011/01/14/introducing-apf-firewall-for-ubuntu-but-you-can-use-this-on-many-other-linux-flavors/</link>
		<comments>http://essayboard.com/2011/01/14/introducing-apf-firewall-for-ubuntu-but-you-can-use-this-on-many-other-linux-flavors/#comments</comments>
		<pubDate>Fri, 14 Jan 2011 04:09:07 +0000</pubDate>
		<dc:creator>Vinh Nguyen</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://essayboard.com/?p=4048</guid>
		<description><![CDATA[Sometimes, you just don&#8217;t want to use the firewall software that are available inside Ubuntu&#8217;s repositories.  Maybe those aren&#8217;t sophisticated enough, and you&#8217;re a sophisticated person.  Maybe you need an elaborated firewall.  Maybe you just want to try out a new firewall.  I like to introduce to you a very good firewall which is known&#8230;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=4048&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sometimes, you just don&#8217;t want to use the firewall software that are available inside Ubuntu&#8217;s repositories.  Maybe those aren&#8217;t sophisticated enough, and you&#8217;re a sophisticated person.  Maybe you need an elaborated firewall.  Maybe you just want to try out a new firewall.  I like to introduce to you a very good firewall which is known as APF.  To my knowledge, many websites that are hosted by many servers rely on APF firewall.  APF firewall is very easy to configure since its configuration file has detail explanation.  Installing it is even easier!  I believe within 10 minutes or less, you can get APF firewall running on your Ubuntu system!</p>
<p>In this blog post, I won&#8217;t go into detail of how to configure your APF firewall since each network is unique and each server is unique.  Each server uses different software, therefore different custom ports are required to be opened.  Instead, I will focus on installing APF firewall, highlighting the important configuration options inside APF&#8217;s configuration file, and showing you how to get APF firewall starting on boot/reboot for your Ubuntu system.</p>
<p>You can download APF firewall at <a href="http://www.rfxn.com/projects/advanced-policy-firewall/" target="_blank">here</a>.  After downloading it, go to the location that you have saved the download of APF, and execute the command [tar xvzf yourdownload-package] &#8212; make sure you replace yourdownload-package with the APF&#8217;s package that you had downloaded earlier.  Change into the APF directory that you had extracted when you executed the command above.  Inside there, execute the command [sh install.sh] without using the square brackets.</p>
<p>Now you can begin to configure your APF firewall.  Just execute the command [vim.tiny /etc/apf/conf.apf].  In conf.apf, you need to read everything so you can change the settings to your liking.  Since each network and server/computer is unique, therefore you must rely on the understanding of your network&#8217;s structure in details.  Still, I&#8217;m going to highlight some important configuration settings you need to change.</p>
<p style="padding-left:30px;">First, if you are ssh into your Ubuntu box remotely, do not change the line that says DEVEL_MODE=&#8221;1&#8243; to DEVEL_MODE=&#8221;0&#8243; until you have satisfied with the changes you have made to file conf.apf.  Also, don&#8217;t leave DEVEL_MODE=&#8221;1&#8243; forever there, because it&#8217;s only a testing mode which prevents you from being locked out of your Ubuntu server/box in case you have made a wrong modification to the file conf.apf.</p>
<p style="padding-left:30px;">Second, on the lines that say IFACE_IN=&#8221;eth0&#8243; and IFACE_OUT=&#8221;eth0&#8243;, make sure you make the right change if you&#8217;re using wireless adapter or virtualization network setting.  If you&#8217;re using normal Ethernet connection for your Ubuntu server/box, then you can just leave these two lines alone.  Still unsure?  You can do ifconfig inside shell/terminal to pull up all network information.</p>
<p style="padding-left:30px;">Third, the line that says IG_TCP_CPORTS= is very important!  Whatever ports you add to this line will allow your Ubuntu server/box to accept incoming connection.  For an example, if you want to make an ssh connection to your Ubuntu server on port 2222 instead of port 22, then you need to remove port 22 and add port 2222 on this line.</p>
<p style="padding-left:30px;">Fourth, the line says EFG=&#8221;0&#8243;, make sure you change this to EFG=&#8221;1&#8243; &#8212; this line tells APF to filter outgoing connection.  Unless you don&#8217;t care about outgoing connection, you must make the change.</p>
<p style="padding-left:30px;">Fifth, the line says EG_TCP_CPORTS= is where you want to prescribe which ports are available for outgoing connection on your Ubuntu server/box.  For an example, if you want your Ubuntu server/box to be able to download software through FTP connection, then you must add port 21 to this line.  Another example, if you want your Ubuntu server/box to be able to connect your browser through a standard port 80 so you can browse the Internet, then you must add port 80 to this line.</p>
<p style="padding-left:30px;">Everything else, you need to read more so you can customize those other settings to you liking.</p>
<p>After you have done with the modification of conf.apf file, please save it!  It&#8217;s now time for you to start your APF firewall and test it to see if your APF firewall is actually blocking and allowing certain ports.</p>
<p>To run or start APF firewall, you need to do [/usr/local/sbin/apf -s].  To restart APF, just do [/usr/local/sbin/apf -r].  When I say you need to do, it means you type whatever inside the square brackets onto your terminal.</p>
<p>Wondering if APF is actually running?  Just do [iptables -L].  If you&#8217;re not familiar with IPFilter, then just open up conf.apf, remove a port you want to use, and try to make the connection to see if your software is blocked or not.  Example, remove port 22 for your ssh connection, and then try to ssh into your Ubuntu server/box to see APF is actually blocking you from making a connection on port 22.  Doing the opposite to see if you can ssh into your Ubuntu server/box.</p>
<p>Here comes another important tip!  Usually, this isn&#8217;t necessary if you&#8217;re running CentOS or Fedora or RedHat, but on Ubuntu, you must edit the file /etc/rc.local by doing [vim.tiny /etc/rc.local], and add the line [sh -c "/etc/apf/apf -s" &amp;] above the line that says [exit 0].  Don&#8217;t use the square brackets!  Save the file /etc/rc.local and then reboot.  So what is this procedure for?  It&#8217;s necessary for Ubuntu to start APF firewall on reboot or on fresh boot.  Usually, other Linux OS would use [chkconfig --add apf] and [chkconfig --level 345 apf on], but since Ubuntu doesn&#8217;t have chkconfig installed by default, therefore you must modify your /etc/rc.local with the line I mentioned above.  When restarting your Ubuntu server/box, you may see a bunch of gibberish code spitting onto your shell, don&#8217;t be alarmed!  Just wait till your shell is stop spitting out code completely, and you can hit the enter key on your keyboard to see the login prompt!  Those gibberish code which spat onto your shell/terminal&#8217;s screen notified you that Ubuntu started APF.  Log inside as root and do [iptables -L] to confirm APF indeed is running!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/essayboard.wordpress.com/4048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/essayboard.wordpress.com/4048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/essayboard.wordpress.com/4048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/essayboard.wordpress.com/4048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/essayboard.wordpress.com/4048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/essayboard.wordpress.com/4048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/essayboard.wordpress.com/4048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/essayboard.wordpress.com/4048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/essayboard.wordpress.com/4048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/essayboard.wordpress.com/4048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/essayboard.wordpress.com/4048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/essayboard.wordpress.com/4048/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/essayboard.wordpress.com/4048/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/essayboard.wordpress.com/4048/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=essayboard.com&amp;blog=24829897&amp;post=4048&amp;subd=essayboard&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://essayboard.com/2011/01/14/introducing-apf-firewall-for-ubuntu-but-you-can-use-this-on-many-other-linux-flavors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8e5039f4535d34121a1108ca8ad38d90?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">argh2xxx</media:title>
		</media:content>
	</item>
	</channel>
</rss>
