Site Meter Tux Watch » Blog Archive » A Sure Way to Securing Linux - Shoreline

A Sure Way to Securing Linux - Shoreline

by

shorewallIf you have been searching for a cool and non-commercial/free Firewall tool for Linux, Shoreline Firewall also known as “Shorewall� may be a good choice. Shorewall uses iptables for configuring Netfilter in Linux and for experienced users, all that an administrator has to do is describe the firewall or gateway requirements using entries in a set of configuration files and Shorewall reads these files. Shorewall, with the help of the iptables utility, configures Netfilter to match user defined requirements. Administrators or even simple Linux users can build dedicated firewall systems, multi-function gateways, routers or servers.

How does it do all this? It does not use Netfilter’s ipchains compatibility mode taking advantage of Netfilter’s connection state tracking capabilities but it is still not a daemon and once Netfilter configured is configured via Shorewall, no “processâ€? related to Shorewall is left running on the system. Shorewall also provides

Shorewall Features:

  • Uses Netfilter’s connection tracking facilities for stateful packet filtering thus can be used in a wide range of router/firewall/gateway applications.
    - Completely customizable using configuration files.
    - No limit on the number of network interfaces.
    - Allows you to partition the network into zones and gives you complete control over the connections permitted between each pair of zones.
    - Multiple interfaces per zone and multiple zones per interface permitted.
    - Supports nested and overlapping zones.
  • Extensive documentation in available in both XML and HTML formats incluing, QuickStart Guides and HowTos.
  • A GUI is available via Webmin 1.060 and later (http://www.webmin.com)
  • Flexible address management/routing support (and you can use all types in the same firewall):
    • Masquerading/SNAT.
    • Port Forwarding (DNAT).
    • One-to-one NAT.
    • Proxy ARP.
    • NETMAP (requires a 2.6 kernel or a patched 2.4 kernel).
  • Blacklisting of individual IP addresses and subnetworks is supported.
  • Operational Support.
    • Commands to start, stop and clear the firewall
    • Supports status monitoring with an audible alarm when an “interestingâ€? packet is detectez.
    • Wide variety of informational commands.
  • VPN Support.
    • IPSEC, GRE, IPIP and OpenVPN Tunnels.
    • PPTP clients and Servers.
    • Support for Traffic Control/Shaping integration
  • Wide support for different GNU/Linux Distributions.
    • RPM and Debian packages available.
    • Includes automated install, upgrade, fallback and uninstall facilities for users who can’t use or choose not to use the RPM or Debian packages.
    • Included as a standard part of LEAF/Bering (router/firewall on a floppy, CD or compact flash).
    • Media Access Control (MAC) Address Verification.
    • Traffic Accounting.
    • Bridge/Firewall support (requires a 2.6 kernel or a patched 2.4 kernel).
Did You Enjoy this Post? Subscribe to Tux Watch. It's Free!

Leave a Reply


About Tux Watch

Are you tired of Windows crashing , removing spyware, viruses, and proprietary lock-in? Are you frustrated with licensing fees and software activation demands? Are you dreading the arrival of Windows Vista, with its increased hardware requirements? Are you willing to try something different?

Tux Watch will search the web for the best resources of software, top articles and tips and even have tutorials to get you started. Linux is a free and open-source operating system that has seen tremendous growth in the past several years. Linux is stable, secure, and very powerful. It is also has tremendous capabilities, far beyond those available with other operating systems. .

Tux Watch Author(s)

Technology Channel Posts

  • Cell Phones + Social Networks = Love?
    [caption id="attachment_262" align="alignnone" width="128" caption="Social Networks"][/caption]Wireless industry ready to interface with Facebook, MySpace and Bebo Everybody at this week's Mobile [...]
  • LG X120 Netbook
    LG Electronics has announced it is launching their newest netbook called the LG X120. The laptop is a cute one with only 10.1″ screen with backlit. Powering it is an Intel Atom processor [...]
  • Uniea Haptique HardShell Case for MacBook
    This hardshell cases for the new MacBook aluminum are made of ABS plastic coupled with soft touch coating. It offers a textured feel, almost leather like, and protects the surface of the laptop [...]
  • Haier shows off it's offerings to the masses
    [caption id="attachment_1757" align="alignnone" width="600" caption="Haier netb ook, G1 and G2"][/caption]The fine folks over at Haier shows off mysterious "NetBooks," Android phones Haier's [...]
  • Hackers target Gamers
    [caption id="attachment_887" align="alignnone" width="128" caption="Xbox"][/caption]Although I'm not a gamer, everyone should be aware of hackers and malware. According to microsoft, What's the [...]
  • Microsoft Equips Individuals With New Training Resources Needed for Jobs
    [caption id="attachment_733" align="alignnone" width="109" caption="Microsoft"][/caption]Second time around for this bit of news, but very apropos in today's business climate. Microsoft Corp. [...]
  • LG Phone's Transparent Keypad Expected to "Make A New Fashion Statement"
    [caption id="attachment_259" align="alignnone" width="950" caption="Transluscent Phone"][/caption][caption id="attachment_258" align="alignnone" width="500" caption="LG GD-900"][/caption]Firmware or [...]
  • Preorder Nokia N86 at Expansys
    [caption id="attachment_1754" align="alignnone" width="162" caption="Nokia N86"][/caption]Engadget breaks this story: European markets can expect to see Nokia's N86 handset on or about July 22, [...]
  • Microsoft Tests Vista SP2, Readies Windows 7 Updates
    [caption id="attachment_884" align="alignnone" width="116" caption="Vista"][/caption]Lots coming out of Redmond these days. Service Pack 2 for Windows Vista and Windows Server 2008 is reportedly [...]
  • Five Steps to an E-friendly RĂ©sumĂ©
    [caption id="attachment_730" align="alignnone" width="128" caption="Resume on Outlook"][/caption]With today's economy and layoffs, we all need all the help we can get when searching for jobs. MSN [...]

Hot Off The Press