Site Meter Tux Watch » Blog Archive » A Sure Way to Securing Linux - Shoreline

A Sure Way to Securing Linux - Shoreline

by Fouad Bajwa

shorewallIf you have been searching for a cool and non-commercial/free Firewall tool for Linux, Shoreline Firewall also known as “Shorewall? may be a good choice. Shorewall uses iptables for configuring Netfilter in Linux and for experienced users, all that an administrator has to do is describe the firewall or gateway requirements using entries in a set of configuration files and Shorewall reads these files. Shorewall, with the help of the iptables utility, configures Netfilter to match user defined requirements. Administrators or even simple Linux users can build dedicated firewall systems, multi-function gateways, routers or servers.

How does it do all this? It does not use Netfilter’s ipchains compatibility mode taking advantage of Netfilter’s connection state tracking capabilities but it is still not a daemon and once Netfilter configured is configured via Shorewall, no “process? related to Shorewall is left running on the system. Shorewall also provides

Shorewall Features:

  • Uses Netfilter’s connection tracking facilities for stateful packet filtering thus can be used in a wide range of router/firewall/gateway applications.
    - Completely customizable using configuration files.
    - No limit on the number of network interfaces.
    - Allows you to partition the network into zones and gives you complete control over the connections permitted between each pair of zones.
    - Multiple interfaces per zone and multiple zones per interface permitted.
    - Supports nested and overlapping zones.
  • Extensive documentation in available in both XML and HTML formats incluing, QuickStart Guides and HowTos.
  • A GUI is available via Webmin 1.060 and later (http://www.webmin.com)
  • Flexible address management/routing support (and you can use all types in the same firewall):
    • Masquerading/SNAT.
    • Port Forwarding (DNAT).
    • One-to-one NAT.
    • Proxy ARP.
    • NETMAP (requires a 2.6 kernel or a patched 2.4 kernel).
  • Blacklisting of individual IP addresses and subnetworks is supported.
  • Operational Support.
    • Commands to start, stop and clear the firewall
    • Supports status monitoring with an audible alarm when an “interesting? packet is detectez.
    • Wide variety of informational commands.
  • VPN Support.
    • IPSEC, GRE, IPIP and OpenVPN Tunnels.
    • PPTP clients and Servers.
    • Support for Traffic Control/Shaping integration
  • Wide support for different GNU/Linux Distributions.
    • RPM and Debian packages available.
    • Includes automated install, upgrade, fallback and uninstall facilities for users who can’t use or choose not to use the RPM or Debian packages.
    • Included as a standard part of LEAF/Bering (router/firewall on a floppy, CD or compact flash).
    • Media Access Control (MAC) Address Verification.
    • Traffic Accounting.
    • Bridge/Firewall support (requires a 2.6 kernel or a patched 2.4 kernel).
Did You Enjoy this Post? Subscribe to Tux Watch. It's Free!

Leave a Reply


About Tux Watch

Are you tired of Windows crashing , removing spyware, viruses, and proprietary lock-in? Are you frustrated with licensing fees and software activation demands? Are you dreading the arrival of Windows Vista, with its increased hardware requirements? Are you willing to try something different?

Tux Watch will search the web for the best resources of software, top articles and tips and even have tutorials to get you started. Linux is a free and open-source operating system that has seen tremendous growth in the past several years. Linux is stable, secure, and very powerful. It is also has tremendous capabilities, far beyond those available with other operating systems. .

Tux Watch Author(s)
    » Jeff-Christman

Technology Channel Posts

Hot Off The Press

  • This Isn't Your Dad's Model Car!
    My kids are new to the Build-a-Bear scene but they love the idea of it. I can see why, you get a basic something and then create whatever you want from there. Both boys and girls love it and [...]
  • Cory in the House for Nintendo DS Review
    The other day I tried out Cory in the House for Nintendo DS as a rental game. The video game is based on the Disney Channel show of the same name. It includes many of the show's characters such [...]
  • Week-long activities educate about transgender daily lives
    Transgender Awareness Week has brought education and attention about transgender issues. Shannon Jolliff, Office of Gay and Lesbian Programs director, said it has been a success on campus. "The [...]
  • Talking to Someone After A Failed Suicide Attempt
    I've screwed up more suicide attempts than I care to admit, so I'm sadly more than qualified to write this article. If you're reading this, chances are you have also gone through a failed suicide [...]
  • "Uncle Tom"?
    Ralph Nader Calls Obama "Uncle Tom"? Video And Transcript http://www.informationclearinghouse.info/article21169.htm Fox News distorts Nader's comments to paint him as a racist Posted [...]
  • Clip of the Week
    This week's clip comes from The Young & the Restless. This is a clip of Nina confronting her husband David Kimble on all of the lies that he had been telling her. This week after seeing Tricia Cast [...]
  • Same Workout, New Pants Size
    Make your usual workout burn more calories -- without working a stitch harder -- with this simple switch: Do cardio before you strength train. Doing cardio first -- brisk walking, cycling, swing [...]
  • FSU weekly news (November 17 - November 21)
    In this edition of FSU Headlines (15:20): - FSU Goes to Omaha - FSU Driving the Future - FSU Making Cents for Students - FSU Going Global - FSU Goes Hands-On with Tuition, Music Subscribe to FSU [...]
  • Your dog lets others know all about you!!!
    [caption id="attachment_839" align="alignnone" width="300" caption="What does this dog say about its owner?"][/caption] More and more people have dogs as members of their families and some research [...]
  • Utley Out Until June 2009?
    This is not good for Phillie fans, not good at all... Three-time All-Star Chase Utley, who anchored the middle of the lineup for the World Series champion Phillies, will have surgery and may [...]