Fred Stluka on 17 Dec 2008 10:05:44 -0800 |
PLUGgers, At the last PLUG West meeting, I asked a question about stateful firewalls. Here's a useful tutorial sent to me by JP Vossen: http://www.obfuscation.org/ipf/ipf-howto.html It's long, but very readable, written in a conversational style with occasional amusing snippets like: "... everyone is going to come looking for your head to place on a platter. So, to keep your head <-> torso network intact ...". and: "The packet is expunged without a peep. There are no notices, no logs, no memorial service. Cake will not be served." It is also very concrete. It explains the basic ideas briefly, but immediately dives into a series of progressive examples of IPFilter rulesets for filtering incoming and outgoing IP packets. Read until you get bored or overwhelmed. Then stop, before your head hurts. It gets more technical and handles more specialized cases as it goes. I made it to the end, but I'll admit I did start skimming. I added a link to my links page for future reference: http://bristle.com/~fred/#firewalls Thanks, JP! --Fred --------------------------------------------------------------------- Fred Stluka -- mailto:fred@bristle.com -- http://bristle.com/~fred/ Bristle Software, Inc -- http://bristle.com -- Glad to be of service! --------------------------------------------------------------------- ___________________________________________________________________________ Philadelphia Linux Users Group -- http://www.phillylinux.org Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug
|
|