public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] iptables advice for stand alone box under different usage scenarios
@ 2005-09-08 16:36 Michael Kintzios
  2005-09-08 17:05 ` Dave Nebinger
  0 siblings, 1 reply; 6+ messages in thread
From: Michael Kintzios @ 2005-09-08 16:36 UTC (permalink / raw
  To: gentoo-user

Hi All,

I know that this has been talked to death, but can I please ask for your
patience as I don't yet feel confident enough to push on without some
more specific advice.

I am contemplating two different set ups as shown is the two diagrams
below:
==============DIAGRAM A===============================================
        |  Router/firewall  +-->(Gentoo box)192.168.0.2 (one NIC only)
Internet|<--Netgear DG834---|
ADSL    |    192.168.0.1    +-->(WinXP box) 192.168.0.3 (one NIC only)
======================================================================
The router here performs NAT, firewalling and DNS duties.

Occasionally, I want to send/receive faxes using a modem and when the
ADSL connection is playing up I have to use good old dial up to connect
to the internet:
==========DIAGRAM B==============
        |           |
Internet|<--modem-->|(Gentoo box)
Dialup  |           |
=================================

Ideally, I would like to setup iptables for the following potential
scenarios:

1.  As shown in diagram (A) above where both boxes operate as
conventional desktops.  I guess iptables is not really needed, but
assume for a minute that my other half just installed a trojan and now a
script kiddie is trying to install a rootkit into my Gentoo box via her
WinXP-bot.  This hypothetical scenario at least presents a good
opportunity for me to learn how to set iptables up in a relatively safe
environment (behind the netgear firewall).

2.  As shown in diagram (B) above where the Gentoo box operates as a
desktop.  Here the box is exposed to the elements and any malicious
entity could compromise it over the dialup interface.

3.  As shown in diagram (A), but now the Gentoo box is no longer a
desktop, but it operates as a www/ftp/mail server and serves both LAN
and WAN clients (I'm fed up paying for unhelpful webhosters ;-).

I can see that I will need to load different iptable set-ups depending
on the network configuration and the role of the Gentoo box
(desktop/server).  Not sure how I switch between them.

Starting from the basics I am also not quite sure how to define my
interfaces.  If the Gentoo box NIC eth0 is the external iface, under
scenario 1, then what's the internal?  I'm asking this because I tried
to setup fwbuilder and it is asking for an internal iface, even for a
stand alone host (am I supposed to setup a loopback?).

Sorry if the above are naïve questions, but iptables is new ground for
me and I thought it's high time I put some effort into learning it.
Whether you feel like scripting out each scenario for me, or you would
rather explain the basic firewall operating philosophy for a particular
usage scenario, I would be most grateful all the same for your help.
-- 
Regards,
Mick


-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2005-09-09 15:56 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-09-08 16:36 [gentoo-user] iptables advice for stand alone box under different usage scenarios Michael Kintzios
2005-09-08 17:05 ` Dave Nebinger
2005-09-08 20:58   ` [gentoo-user] " Mick
2005-09-08 20:27     ` Dave Nebinger
2005-09-09 15:19       ` Michael Kintzios
2005-09-09 15:49         ` Dave Nebinger

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox