From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Lawrence - D" Subject: Firewall software Date: Tue, 5 Aug 2003 18:22:58 +1000 Sender: netfilter-admin@lists.netfilter.org Message-ID: <003801c35b2a$c9a8c1e0$7700000a@lawrencewin2k> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0035_01C35B7E.9923E820" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Netfilter This is a multi-part message in MIME format. ------=_NextPart_000_0035_01C35B7E.9923E820 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi, Can anyone recommend firewall software that can work together with = IPtables ? User friendly interface. Lawrence Tang=20 ------=_NextPart_000_0035_01C35B7E.9923E820 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hi,
    Can anyone=20 recommend firewall software that can work together with IPtables ? = User=20 friendly interface.
 
 
Lawrence Tang =
------=_NextPart_000_0035_01C35B7E.9923E820-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tom Van Overbeke Subject: RE: Firewall software Date: Tue, 05 Aug 2003 10:47:18 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <000c01c35b2e$2de52100$d90315ac@rsrc.be.local> References: <003801c35b2a$c9a8c1e0$7700000a@lawrencewin2k> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="Boundary_(ID_ghnwSy9gg+KjdVk3LvB44A)" Return-path: In-reply-to: <003801c35b2a$c9a8c1e0$7700000a@lawrencewin2k> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: 'Lawrence - D' , "Netfilter (E-mail)" This is a multi-part message in MIME format. --Boundary_(ID_ghnwSy9gg+KjdVk3LvB44A) Content-type: text/plain; charset=iso-8859-1 Content-transfer-encoding: 7BIT fwbuilder & firepoint fwbuilder is a graphic interface with icons representing various firewall objects (hosts, firewalls, tcp ports), which makes it a lot easier to create a decent firewall policy. firepoint is a wrapper around fwbuilder with as main features access control & automatic activation of firewall policy. firepoint is not perfect (access control is actually not very secure), but this combo together with iptables enables one to create a rather professional firewall setup. Tom. -----Original Message----- From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of Lawrence - D Sent: 05 August 2003 10:23 To: Netfilter Subject: Firewall software Hi, Can anyone recommend firewall software that can work together with IPtables ? User friendly interface. Lawrence Tang **************************************************************************** Disclaimer: This electronic transmission and any files attached to it are strictly confidential and intended solely for the addressee. If you are not the intended addressee, you must not disclose, copy or take any action in reliance of this transmission. If you have received this transmission in error, please notify the sender by return and delete the transmission. Although the sender endeavors to maintain a computer virus free network, the sender does not warrant that this transmission is virus-free and will not be liable for any damages resulting from any virus transmitted. Thank You. **************************************************************************** --Boundary_(ID_ghnwSy9gg+KjdVk3LvB44A) Content-type: text/html; charset=iso-8859-1 Content-transfer-encoding: 7BIT
fwbuilder & firepoint
 
 
fwbuilder is a graphic interface with icons representing various firewall objects (hosts, firewalls, tcp ports), which makes it a lot easier to create a decent firewall policy.
 
firepoint is a wrapper around fwbuilder with as main features access control & automatic activation of firewall policy. firepoint is not perfect (access control is actually not very secure), but this combo together with iptables enables one to create a rather professional firewall setup.
 
 
Tom.
 
-----Original Message-----
From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of Lawrence - D
Sent: 05 August 2003 10:23
To: Netfilter
Subject: Firewall software

Hi,
    Can anyone recommend firewall software that can work together with IPtables ? User friendly interface.
 
 
Lawrence Tang
****************************************************************************
Disclaimer: 
This electronic transmission and any files attached to it are strictly 
confidential and intended solely for the addressee. If you are not 
the intended addressee, you must not disclose, copy or take any
action in reliance of this transmission. If you have received this 
transmission in error, please notify the sender by return and delete
the transmission.  Although the sender endeavors to maintain a
computer virus free network, the sender does not warrant that this
transmission is virus-free and will not be liable for any damages 
resulting from any virus transmitted. 
Thank You.
****************************************************************************
--Boundary_(ID_ghnwSy9gg+KjdVk3LvB44A)-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: pammann@execomm.net (Paul Ammann) Subject: Re: Firewall software Date: Tue, 5 Aug 2003 04:46:08 -0700 Sender: netfilter-admin@lists.netfilter.org Message-ID: <001201c35b47$2c5c06a0$6ee00b42@na6xxo6g5tg9af> References: <003801c35b2a$c9a8c1e0$7700000a@lawrencewin2k> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_000D_01C35B0C.7CA6FEC0" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Lawrence - D , Netfilter This is a multi-part message in MIME format. ------=_NextPart_000_000D_01C35B0C.7CA6FEC0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Go to Sourceforge, and look up Firewall Builder. This VERY user friendly = interface interacts with IPtables as well as PIX. Best regards, Paul Ammann ----- Original Message -----=20 From: Lawrence - D=20 To: Netfilter=20 Sent: Tuesday, August 05, 2003 1:22 AM Subject: Firewall software Hi, Can anyone recommend firewall software that can work together with = IPtables ? User friendly interface. Lawrence Tang=20 ------=_NextPart_000_000D_01C35B0C.7CA6FEC0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Go to Sourceforge, and look up Firewall = Builder.=20 This VERY user friendly interface interacts with IPtables as well as=20 PIX.
 
Best regards,
 
Paul Ammann
 
----- Original Message -----
From:=20 Lawrence - D
To: Netfilter
Sent: Tuesday, August 05, 2003 = 1:22=20 AM
Subject: Firewall = software

Hi,
    Can anyone=20 recommend firewall software that can work together with IPtables = ? User=20 friendly interface.
 
 
Lawrence Tang=20
------=_NextPart_000_000D_01C35B0C.7CA6FEC0-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Lawrence - D" Subject: Re: Firewall software Date: Tue, 5 Aug 2003 19:02:08 +1000 Sender: netfilter-admin@lists.netfilter.org Message-ID: <003a01c35b30$41204ea0$7700000a@lawrencewin2k> References: <003801c35b2a$c9a8c1e0$7700000a@lawrencewin2k> <001201c35b47$2c5c06a0$6ee00b42@na6xxo6g5tg9af> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0037_01C35B84.11A87810" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Paul Ammann , Netfilter This is a multi-part message in MIME format. ------=_NextPart_000_0037_01C35B84.11A87810 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable thanks guy. Lawrence ----- Original Message -----=20 From: Paul Ammann=20 To: Lawrence - D ; Netfilter=20 Sent: Tuesday, August 05, 2003 9:46 PM Subject: Re: Firewall software Go to Sourceforge, and look up Firewall Builder. This VERY user = friendly interface interacts with IPtables as well as PIX. Best regards, Paul Ammann ----- Original Message -----=20 From: Lawrence - D=20 To: Netfilter=20 Sent: Tuesday, August 05, 2003 1:22 AM Subject: Firewall software Hi, Can anyone recommend firewall software that can work together = with IPtables ? User friendly interface. Lawrence Tang=20 ------=_NextPart_000_0037_01C35B84.11A87810 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
thanks guy.
 
Lawrence
----- Original Message -----
From:=20 Paul Ammann=20
To: Lawrence - D ; Netfilter
Sent: Tuesday, August 05, 2003 = 9:46=20 PM
Subject: Re: Firewall = software

Go to Sourceforge, and look up = Firewall Builder.=20 This VERY user friendly interface interacts with IPtables as well as=20 PIX.
 
Best regards,
 
Paul Ammann
 
----- Original Message -----
From:=20 Lawrence - D
To: Netfilter
Sent: Tuesday, August 05, = 2003 1:22=20 AM
Subject: Firewall = software

Hi,
    Can anyone=20 recommend firewall software that can work together with = IPtables ? User=20 friendly interface.
 
 
Lawrence Tang=20
------=_NextPart_000_0037_01C35B84.11A87810-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Brad Morgan" Subject: How to allow Real Player Date: Tue, 12 Aug 2003 21:56:31 -0600 Sender: netfilter-admin@lists.netfilter.org Message-ID: <000001c3614e$e5eeed50$0400a8c0@bradmorgan> References: <000c01c35b2e$2de52100$d90315ac@rsrc.be.local> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <000c01c35b2e$2de52100$d90315ac@rsrc.be.local> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: "'Netfilter (E-mail)'" I'm trying to understand how to setup my firewall to allow Real Player. Based on the text below, I've written the following rules:=20 ## Allow Real Player for i in $LANIPS; do iptables -A FORWARD -p tcp -s $i --dport 554 -j ACCEPT iptables -A FORWARD -p tcp -s $i --dport 7070 -j ACCEPT done iptables -A FORWARD -p udp --dport 6970:6979 -j ACCEPT I limited the number of UDP ports to a much smaller range than they = suggest. This network has both public IP addresses and NAT addresses (a = conversion to use just the NAT address range is taking place). My test user is on one = of the NAT addresses. What I don't understand is the statement "The range of UDP ports, on the other hand, carries the incoming stream. These ports begin to carry = traffic only after RealPlayer and RealServer have performed the authentication routine, and should be enabled only for incoming traffic." Is the firewall going to know what to do with an incoming packet to one = of these UDP ports? If the internal machine initiated the conversation, = then ESTABLISHED would know what to do, but that would be outgoing traffic = which the documentation says won't happen. Is this another one of those applications that needs a "helper"? Does = one exist? I looked but couldn't find it. Strange thing is, the user's web cast worked after adding the above = rules, but capturing the traffic using Ethereal didn't show any UDP traffic at = all, only TCP and RSTP on 554. I did however, see realplayer.exe listening = on UDP port 6970. Thanks for your insight. Regards, Brad Morgan =20 ----- Excerpt from http://service.real.com/firewall/adminfw.html ----- Application-level Firewalls=20 Your firewall must be RealPlayer-aware. If it is not, RealNetworks has a free RTSP proxy service which includes source code and specifications = for building your own proxy. It's simple and easy to set up. To get your = copy, send an e-mail request to firewall@real.com. You will get an immediate response telling you where to download the proxy.=20 Most major firewall vendors support RealPlayer. If your firewall vendor = is not listed as supporting RealPlayer, ask your firewall representative to contact us about joining our firewall developers program.=20 Network-level Firewalls Network-level firewalls, such as packet filters, use access control = lists to allow traffic destined for some ports to pass from the Internet to the organization's internal network and to block packets for other ports. To allow any version of RealAudio Player or RealPlayer to play correctly, = it is only necessary for the router to allow packets to pass to the inner = network that are bound for the following range of ports: TCP port 7070 for connecting to pre-G2 RealServers TCP port 554 and 7070 for connecting to G2 RealServers=20 UDP ports 6970 - 7170 (inclusive) for incoming traffic only=20 The TCP port is used by RealPlayer to initiate a conversation with an external RealServer, to authenticate RealPlayer to the server, and to = pass control messages during playback (such as pausing or stopping the = stream). RealSystem G2 uses two TCP protocols for conversations between Players = and Servers.=20 For an even safer firewall, configure the router's access control list = to allow TCP connections on port 7070 and/or port 554 to be initiated from = the inside network exclusively. Incoming traffic, on the other hand, should = only be allowed if it is part of an ongoing connection. This is assured by requiring incoming TCP packets to have the ACK bit set in the TCP header carried by every packet. The syntax for setting the ACK bit varies with = the kind of router you own. For Cisco routers the flag "ESTABLISHED" can be = put at the end of the line in an access rule to specify that an incoming = packet must be part of an ongoing conversation.=20 The range of UDP ports, on the other hand, carries the incoming stream. These ports begin to carry traffic only after RealPlayer and RealServer = have performed the authentication routine, and should be enabled only for incoming traffic.=20 You may also want to use a proxy server in conjunction with a = network-level firewall.=20 =20 From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tom Marshall Subject: Re: How to allow Real Player Date: Wed, 13 Aug 2003 13:24:02 -0700 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20030813202402.GA11672@home.tig-grr.com> References: <000c01c35b2e$2de52100$d90315ac@rsrc.be.local> <000001c3614e$e5eeed50$0400a8c0@bradmorgan> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="Dxnq1zWXvFF0Q93v" Return-path: Content-Disposition: inline In-Reply-To: <000001c3614e$e5eeed50$0400a8c0@bradmorgan> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Brad Morgan Cc: "'Netfilter (E-mail)'" --Dxnq1zWXvFF0Q93v Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Please note most of the following discussion applies to RTSP in general, not just RealPlayer. On Tue, Aug 12, 2003 at 09:56:31PM -0600, Brad Morgan wrote: > I'm trying to understand how to setup my firewall to allow Real Player. > Based on the text below, I've written the following rules:=20 >=20 > ## Allow Real Player > for i in $LANIPS; do > iptables -A FORWARD -p tcp -s $i --dport 554 -j ACCEPT > iptables -A FORWARD -p tcp -s $i --dport 7070 -j ACCEPT > done > iptables -A FORWARD -p udp --dport 6970:6979 -j ACCEPT >=20 > I limited the number of UDP ports to a much smaller range than they sugge= st. The RTSP protocol normally uses TCP port 554. Port 7070 is for an old proprietary protocol called PNA that has been deprecated for over 5 years. You may still run into it occasionally, but hopefully that is rare. RTSP is a control protocol. It does the equivalent of the play/pause/stop buttons. The actual data can flow either in separate UDP packets (this is preferred), or interleaved within the same TCP connection as RTSP. > What I don't understand is the statement "The range of UDP ports, on the > other hand, carries the incoming stream. These ports begin to carry traff= ic > only after RealPlayer and RealServer have performed the authentication > routine, and should be enabled only for incoming traffic." >=20 > Is the firewall going to know what to do with an incoming packet to one of > these UDP ports? If the internal machine initiated the conversation, then > ESTABLISHED would know what to do, but that would be outgoing traffic whi= ch > the documentation says won't happen. When using UDP, the server usually starts sending packets to the client first. This means that the NAT does not have a chance to create a mapping between client and server, so it doesn't know where to send the UDP packets= .=20 Newer clients are getting around this problem with techniques such as STUN and Symmetric RTP, but most clients don't have this ability. > Is this another one of those applications that needs a "helper"? Does one > exist? I looked but couldn't find it. Bingo! :-) In order to solve this problem, you need to use an RTSP ALG (helper module)= .=20 I wrote one for the 2.4.21-preX kernels some months ago. It's not been updated in some time due to lack of response. The changes to get the patch running on the released 2.4.21 kernel are fairly trivial. You can download it here: http://home.tig-grr.com/rtsp/index.html Only 2.4.21-preX is listed at the moment. I plan to update the module at some point in the near future and support various kernel versions.=20 Eventually it would be nice to get the module into the Linux kernel. > Strange thing is, the user's web cast worked after adding the above rules, > but capturing the traffic using Ethereal didn't show any UDP traffic at a= ll, > only TCP and RSTP on 554. I did however, see realplayer.exe listening on > UDP port 6970. Typically, the client will realize after a few seconds that it's not getting any packets and switch over to TCP mode. Some of the more intelligent clients (such as RealONE players) will remember which servers are not accessible via UDP and they won't attempt UDP from that server again for some time. This is may be why you aren't seeing any UDP packets from the server on any arbitrary request. --=20 I've finally learned what "upward compatible" means. It means we get to keep all our old mistakes. -- Dennie van Tassel --Dxnq1zWXvFF0Q93v Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iEYEARECAAYFAj86nmIACgkQFMm9uvwPXW5uwACgjjLK+Omd3e2ZjwQmb/8xB5NB aaMAoIVQuASGX0cNHzfG0J8T+CsFQpth =KpUf -----END PGP SIGNATURE----- --Dxnq1zWXvFF0Q93v--