SuSELinuxFirewallonCD2
Figure 3.47: Destination NAT for VPN ConnectionsPage 1/2 IPSec VPN TunnelFirst, the certificate for Nuremberg is selected. To do this, click ‘Select Ce
3Firewall Administration System (FAS)The Frankfurt branch should have full access to the internal network:Local Subnet activatedSubnet Address 192.168
1. General settingsConnection Name SalesRepsConnection Type Wait for the connection (Server Mode)Settings for PFS Setting, Key Life Time, and Key Repl
3Firewall Administration System (FAS)Figure 3.48: Configuration of Mail Relay — Dialog 1ISP Relay Activate this check box to forward all outgoing e-mai
Figure 3.49: Configuration of Mail Relay — Dialog 2With ‘Next’, complete the configuration of the mail relay.The Example, Inc., ConfigurationPage 1/2 Mai
3Firewall Administration System (FAS)proxy. With the netmask, this is reduced to a single computer:Local Networks 192.168.8.10/32All other parameters
sion 2 of SSH, the files id-dss.pub and id-rsa.pub are involved.Select them and the key appears in the list (see Figure 3.51).Figure 3.51: Import KeyEn
3Firewall Administration System (FAS)The Example, Inc., ConfigurationPage 1/2 Administration via SSHRemote access to the firewall should be possible onl
Figure 3.52: Specifying the NTP Time ServerAssuming you have activated the forwarding of log files for all active firewallconfigurations to the Adminhost
3Firewall Administration System (FAS)the window, providing a summary of the data recorded. This view is dividedas follows:SYSLOG Configuration Name of
1IntroductionIntroductionThe importance of the Internet, the communication possibilities provided, andthe information-gathering options offered seem t
Evaluating the Log FilesLog files often become very large, depending on the type of data recordedand the duration of recording. With the search mask of
3Firewall Administration System (FAS)Figure 3.53: IP Filter StatisticsBlocked Packet Report A pie chart shows the proportion of packets blockedgrouped
Domain Report This report is similar to the ‘Organization Report’, however,sorting is done according to domain extensions, such as .com.Packet Size Re
3Firewall Administration System (FAS)Figure 3.54: Interface StatisticsCertificate ManagementAccess the certificate management module in FAS with ‘Tools’
Figure 3.55: List of Certificateshave them signed. You can also generate your own CA and sign your certifi-cates yourself. This is sufficient for most pu
3Firewall Administration System (FAS)Key size: Choose the key size here. A longer key is more difficult tohack. Choose 1024 or 2048 bits.After you have
Figure 3.56: Dialog for Creating CertificatesExporting CertificatesSelect ‘Certificate Management’ ➝ ‘Export Certificate’. There are three differ-ent form
3Firewall Administration System (FAS)Saving the ConfigurationSave your configuration by clicking ‘Configuration’ ➝ ‘Save’ or ‘Save All’. Ifyou try to lea
online help. To leave the file editor, select ‘Finish’ from the menu. Save yourmodifications to configuration files by pressing ‘Finish’.Testing the Config
3Firewall Administration System (FAS)Documenting Configuration, Tests, and Re-sultsIt is very important to document the configuration, the tests conduct
Most companies rely on their own networks to exchange and process mission-critical information for in-house purposes, such as an intranet, databases,a
4SuSE Live CD for FirewallSuSE Live CD for FirewallThe Live CD for the SuSE Firewall on CD is the executable part of the fire-wall. It is a minimal SuS
Using proxies and not forwarding IP packets are not enough to prevent un-desired Internet IP packets from reaching the intranet or vice versa. Thisfire
4SuSE Live CD for FirewallDescriptionThe SuSE Linux Live CD for Firewall is a live file system CD from which allthe applications run directly. Theoreti
pppoed DSL supportfasfw FAS net filter scriptsyslogd Daemon for system loggingiptables Packet filtercron and logrotate Rotation of local log filesTo comp
4SuSE Live CD for FirewalliptablesA typical iptables filter rule is very simple in theory. It normally consists offour parts:1. a basic operation with
Figure 4.1: Course of a Packet with iptablesPREROUTING, OUTPUT, and POSTROUTING. Figure 4.1 attempts to illustratethe interplay of nat and filter tabl
4SuSE Live CD for FirewallProtocol type: TCP, UDP, ICMPSource portDestination portICMP typeSource addressDestination addressInterface: eth0, ppp0, etc
ICMP Because ICMP packets do not use any port numbers, other selectioncriteria must be used. A list of possible parameters can be obtainedwith the com
4SuSE Live CD for FirewallSubsequent Treatment of Packets (Targets)After a packet has been successfully identified, a rule must know what itshould do w
1Introductionfirewalls is to fend off attacks directed at your intranet as well as to regulate andprotect clients on your LAN by imposing an access pol
Figure 4.2: Comparing IPSec and SSLthe network can be encrypted as well as the communication between singlecomputers or subnetworks.It is no problem t
4SuSE Live CD for Firewallonly valid for a short period. If necessary, a rekey process can be started whilethe connection still exists to replace the
SquidSquid is an HTTP proxy that offers extensive configuration options. Con-trol over the network clients’ access to the web is implemented by means o
4SuSE Live CD for FirewallExternal to InternalTo operate an FTP server, define the settings in this part of the module toenable access from the Interne
with an ext2 file system and contain the label "SuSE-FWFloppy". Without thislabel, the configuration floppy is not recognized. The FAS (Firewal
4SuSE Live CD for FirewallIf necessary, additional options can be passed to the module, such asthe IRQ or the IO addresses of the hardware used. Lines
/etc/rc.config SuSE Linux central configuration file./etc/rc.config.d/ This directory contains files used when services arestarted, for example:/etc/rc.co
4SuSE Live CD for FirewallCautionNo password may be specified for any existing users apart fromroot. Do not change this file.Caution/etc/squid.conf Confi
/opt the contents of the /opt directory on the configuration floppy arecopied to the running system in /opt. The user can store his files inthis director
5IPsec Client on Windows XP and Windows 2000IPsec Client on Win-dows XP and Windows 2000You can configure the connection manually with the program ipse
our case, is based on the concept of an application-level gateway combined withIP packet filtering. The firewall’s routing and gateway capabilities are
to connect to Windows 2000. The ServicePack2 is available from http://www.microsoft.com/windows2000/downloads/servicepacks/sp2/sp2lang.asp.For Windows
5IPsec Client on Windows XP and Windows 2000Importing a Root CertificateRight-click ‘Trusted Root Certificates’. In the drop-down menu, select ‘AllTasks
Editing ipsec.confGo to the directory C:\ProgramFiles\IPsec. Open the file ipsec.confwith an editor. Adjust the data following the syntax in example 6.
5IPsec Client on Windows XP and Windows 2000Closing the ConnectionTo deactivate the IPsec filters and the tunnel, enter IPSEC.exe -delete.Create deskto
6Implementing the FirewallImplementing the FirewallOn the Adminhost, you created a configuration for the Live CD using FAS ormanually created a configur
Requirements for Successful ImplementationFirst, check to see if your host boots using the configuration set up. Also seeif the selected services start
6Implementing the Firewalland process requests properly. Adminhost tools are available on the firewallfor these purposes (see 2 on page 15), such as nm
External TestingTest externally to see if the available services are working. For instance, ifyou can send e-mails to the internal network. You should
7HelpHelpIn this chapter, find information about creating a setup concept for a firewallsolution in your network using the SuSE Firewall on CD. Also find
1IntroductionELSA Quickstep 1000 PCIGeneric HFC 2BDSO PCISCSI Host Adapters:53c7,8xx: NCR 53c7,8xx (old driver)AM53C974: AM53/79C974BusLogic: BusLogic
TroubleshootingFind help here if the Adminhost cannot be installed or if the Live CD is notbooting.Problems Installing the AdminhostIf you have troubl
7HelpIs external access to available resources not functioning? Which servicesare affected? Should the resources really be accessible?Test, using ps,
Recognizing an IntrusionFirst, understand which actions are defined as intrusions. Unfortunately, itis normal these days that a host connected to the I
7HelpList all running processes with ps and search for processes that do nottypically occur in normal firewall operation.Draw up a process table when s
External AttacksInform the system administrator responsible for the address block (via post-master or the domain’s abuse address). The report of an in
7HelpExamples:Log in to the console.Examine the log files for messages of the IP filter.Search for certain unusual IP addresses (frequently occurring re
Recommended ReadingD. Brent Chapman & Elizabeth D. Zwicky: Building Internet Firewalls,2nd edition, O’Reilly 2000.Maximum Linux Security, SAMS 199
8Suppor t, Maintenance, and Patch ManagementSupport, Maintenance,and Patch ManagementMaintenanceWith SuSE Maintenance, always have the most up-to-date
Patches for the Admin CDThere are two possibilities here:Via the SuSE Maintenance WebLog in to the SuSE Maintenance Web and download patches individua
8Suppor t, Maintenance, and Patch ManagementAdmin CD, download the patches via the SuSE Maintenance Web and burnthe ISO file to a CD. Find instructions
psi240i: PSI-240iqlogicfas: Qlogic FASqlogicfc: QLogic ISP 2100 SCSI-FCPqlogicisp: QLogic ISP 1020qlogicpti: PTI Qlogic ISP Driverseagate: Seagate ST-
speed sets the speed of the burning process-eject ejects the CD after burning is completedFind more options in the man page for cdrecord (man cdrecord
8Suppor t, Maintenance, and Patch ManagementMail:Address: SuSE Linux AG— Support —Deutschhernnstr. 15-19D-90429 NürnbergProcessing: weekdaysCommercial
D-90429 NürnbergTel: +49-911-740-53-0Fax: +49-911-740-53-479E-mail: [email protected] by our Regional Service Centers in Germany and outside, as
8Suppor t, Maintenance, and Patch ManagementFeedbackWe always appreciate your tips, hints, and problem descriptions. We willhelp you if your problem i
[email protected] — Discussion of security issues in [email protected] — Announcement of security-related errors and upd
ADNS — Domain Name ServiceDNS — Domain Name ServiceDNS (Domain Name Service) is needed to resolve domain and host namesinto IP addresses. This chapter
Starting the Name Server BINDThe name server BIND is already preconfigured in SuSE Linux, so you caneasily start it right after installing the distribu
ADNS — Domain Name Serviceoptions {directory "/var/lib/named";forwarders { 10.11.12.13; 10.11.12.14; };listen-on { 127.0.0.1; 192.168.0.99;
};zone "0.0.127.in-addr.arpa" in {type master;file "127.0.0.zone";};zone "." in {type hint;file "root.hint";};
ADNS — Domain Name Serviceallow-query 127.0.0.1; 192.168.1/24; ; defines the networks from whichclients can post DNS requests. The /24 at the end is an
1Introductiondepca: DEPCA,DE10x,DE200,DE201,DE202,DE422dgrs: Digi Intl. RightSwitch SE-Xdmfe: DM9102 PCI Fast Ethernete100.o: EtherExpress PRO/100 (In
Zone Entry Structurezone "my-domain.de" in{type master;file "my-domain.zone";notify no;};File 11: Zone Entry for my-domain.deAfter
ADNS — Domain Name Servicemasters { 10.0.0.1; }; This entry is only needed for slave zones. It specifiesfrom which name server the zone file should be t
Line 1: $TTL defines the standard TTL that applies for all the entries in thisfile, here 2 days. TTL means “time to live”.Line 2: The SOA control record
ADNS — Domain Name ServiceLine 9: The IN NS specifies the name server responsible for this do-main. The same is true here that gateway is extended to g
Line 1: $TTL defines the standard TTL that applies to all entries here.Line 2: ’Reverse lookup’ should be activated with this file for the network192.16
BProxy Server: SquidProxy Server: SquidThe following chapter describes how caching web sites assisted by a proxyserver works and what the advantages o
What is a Proxy Cache?Squid acts as a proxy cache. It behaves like an agent that receives requestsfrom clients, in this case web browsers, and passes
BProxy Server: SquidMultiple Caches“Multiple caches” means configuring different caches so that objects can beexchanged between them, reducing the tota
The question remains as to how long all the other objects stored in the cacheshould stay there. To determine this, all objects in the cache are assign
BProxy Server: Squidrequests per second = 1000 / seek timeSquid enables more disks to be used simultaneously, increasing the numberof requests per sec
smc9194: SMC 9194tlan: Compaq Netelligent 10/100/NetFlex 3tulip: DEC Tulip (DC21x4x) PCIvia-rhine: VIA VT86c100A Rhine-IIwd: Western Digital WD80x3yel
time of a hard disk, about 10 milliseconds, with the 10 nanoseconds accesstime of the newer RAM memories)Every object in RAM memory has a size of 72 b
BProxy Server: Squidproxy in the browser. To allow all users to access Squid and thus the In-ternet, change the entry in the configuration file /etc/squ
If you have updated an earlier Squid version, it is recommended to edit thenew /etc/squid.conf and only apply the changes made in the previousfile. If
BProxy Server: Squidcache_store_log /var/squid/logs/store.log path for log messageThese three entries specify the path where Squid will log all of its
Squid will make a note of the failed requests then refuse to issue newones, although the Internet connection has been reestablished. In a casesuch as
BProxy Server: Squidshould always be http_access deny all. In the following example,the localhost has free access to everything while all other hosts
ident_lookup_access allow hacl_namei With this, you will manage to havean ident request run through for all ACL-defined clients to find outeach user’s i
BProxy Server: SquidKernel ConfigurationFirst, make sure that the proxy server’s kernel has support for transparentproxies. Otherwise, add this option
SquidGuard is a free (GPL), flexible, and ultra fast filter, redirector, and “ac-cess controller plugin” for Squid. It lets you define multiple access ru
BProxy Server: SquidNow, tell Squid to use SquidGuard. Use the following entries in the /etc/squid.conf file:redirect_program /usr/bin/squidGuardThere
1IntroductionSecurity PolicyThe security policy provides the basis for working with all programs, hosts,and data. In addition, it outlines how to guar
Another powerful cache report generator tool is SARG (Squid Analysis Re-port Generator), included in series n. Further information on this can befound
CNetwork SecurityNetwor k SecurityThis chapter provides detailed information about several aspects of networksecurity. It begins with information abou
Masquerading and FirewallsOwing to its outstanding network capabilities, Linux is becoming morewidespread as a router operating system for dial-up or
CNetwork SecurityNoteMake sure that both the broadcast addresses and the network masksare the same for all the hosts when configuring your network.Note
For such a connection, there would be no entry in the table because, the en-try itself is only created if an internal host opens a connection with the
CNetwork Securityallowed through. This gateway or proxy pretends to be the actual client ofthe server. In a sense, such a proxy could be considered a
For a firewall without masquerading, only set this to yes if you wantto allow access to the internal network. Your internal hosts need to useofficially
CNetwork SecurityFor example: "172.20.0.0/16 172.30.4.2" means that all hostswhich have an IP address beginning with 172.20.x.x, along with
SSH — Secure Shell, the Safe AlternativeIn these times of increasing networks, accessing a remote system also be-comes more common. Regardless of the
CNetwork SecurityFollowing successful authentication, work from the command linethere or use interactive applications. If the local user name is diffe
1st edition 2002Copyright ©This publication is intellectual property of SuSE Linux AG.Its contents can be duplicated, either in part or in whole, prov
Protocol icmp ftp ssh smtp http https . . .Client internal external i. e. i. e. i. e. i. e. i. e.host1 x – x – – – x – x – –host2 x – – – x – x – – –
The SSH Daemon (sshd) — Server-SideTo work with the SSH client programs ssh and scp, a server, the SSH dae-mon, has to be running in the background. T
CNetwork SecurityIt is recommended to securely archive the private and public keys stored in/etc/ssh/ externally. In this way, key modifications can be
ssh-agent, which retains the private keys for the duration of an X session.The entire X session will be started as a child process of ssh-agents. Thee
CNetwork Securityusers in an existing SSH connection. The SMTP and POP3 host must be setto localhost for this.Additional information can be found in t
using a network linkIn all these cases, a user should be authenticated before accessing the re-sources or data in question. A web server might be less
CNetwork Securityserial terminals are a special case. Unlike network interfaces, they do notrely on a network protocol to communicate with the host. A
This is a general rule to be observed, but it is especially true for the userroot who holds the supreme power on the system. User root can take onthe
CNetwork Securitybuddy” or “jasmine76” are easily guessed even by someone who has onlysome casual knowledge about you.The Boot ProcedureConfigure your
directory. The purpose of these files is to define special permissions, suchas world-writable directories or, for files, the setuser ID bits, which means
CNetwork Securityhave serious consequences, in particular if the program is being executedwith special privileges (see Section C on page 199).“Format
1IntroductionFigure 1.2: Simple SetupFigure 1.3: Effective and Manageable Setupstops any illegal requests at the packet level. Packets allowed through
Network SecurityLocal security is concerned with keeping different users on one system apartfrom each other, especially from root. Network security, o
CNetwork SecurityID card of some kind. This cookie (the word goes back not to ordinary cook-ies, but to Chinese fortune cookies which contain an epigr
posted on the security mailing lists. They can be used to target the vulnera-bility without knowing the details of the code. Over the years, experienc
CNetwork SecurityFinally, we want to mention “spoofing”, an attack where packets are modifiedto contain counterfeit source data, mostly the IP address.
very good way to protect your systems against problems of all kinds is to getand install the updated packages recommended by security announcementsas
CNetwork Securityintended to be available in the first place (the legacy problem). Openports, with the socket state LISTEN, can be found with the progr
the end, only you can know which entries are unusual and which arenot.Use tcp_wrapper to restrict access to the individual services run-ning on your m
DYaST and SuSE Linux License TermsYaST and SuSE LinuxLicense TermsYaST 2 Copyright (c) 1995 - 2001 SuSE GmbH, Nuernberg (Germany)YaST 2 Copyright (c)
programmes are observed. The use of YaST2, even if a modified versionis used, does not exempt in particular the Licensee from the duty totake due care
DYaST and SuSE Linux License Termssources and this licence in accordance with 2b. Making YaST2 or worksderived thereof available free of charge togeth
EThe GNU General Public LicenseThe GNU Gen-eral Public LicenseGNU General Public LicenseCopyright (C) 1989, 1991 Free Software Foundation, Inc.59 Temp
the software or use pieces of it in new free programs; and that you know youcan do these things.To protect your rights, we need to make restrictions t
EThe GNU General Public Licenseconstitute a work based on the Program (independent of having been madeby running the Program). Whether that is true de
whole which is a work based on the Program, the distribution of the wholemust be on the terms of this License, whose permissions for other licenseesex
EThe GNU General Public Licensebinary form) with the major components (compiler, kernel, and so on) of theoperating system on which the executable run
only way you could satisfy both it and this License would be to refrain en-tirely from distribution of the Program.If any portion of this section is h
EThe GNU General Public LicenseOur decision will be guided by the two goals of preserving the free status ofall derivatives of our free software and o
published by the Free Software Foundation; either version 2 ofthe License, or (at your option) any later version.This program is distributed in the ho
IndexAACLs- arranging . . . . . . . . . . . . . . . . . . . . . . . . . 77- defining . . . . . . . . . . . . . . . . . . . . . . . . . . 75Adminhost .
2SuSE Adminhost for FirewallSuSE Adminhost for FirewallIt is no easy task to administer, maintain, and monitor a firewall. Above all, theimportance of
- ntp.conf . . . . . . . . . . . . . . . . . . . . . . . . . 127- pam.d . . . . . . . . . . . . . . . . . . . . . . . . . . . 127- permissions . . . .
- proxy filters . . . . . . . . . . . . . . . . . . . . . . 78httpf . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124Iifconfig
Rroot- password . . . . . . . . . . . . . . . . . . . . . . . . . 20routing- masquerading . . . . . . . . . . . . . . . . . . . 184RPM- security . . .
upgrading- VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31users- fwadmin . . . . . . . . . . . . . . . . . . . . . . . . . . 34VVPN
After installing the SuSE Adminhost for Firewall, theFirewall Administration System (FAS) is available. The FAS is a tool with agraphical administrati
2SuSE Adminhost for FirewallTab moves the focus forward an entry or selection field or a button.Shift +Tab moves the focus to the previous
Figure 2.1: YaST2: Keyboard Layout and Time ZoneNow test your keyboard. By clicking with the mouse or usingTab , activatethe entry line and type i
2SuSE Adminhost for FirewallFigure 2.2: YaST2: Preparing the Hard DiskStep 2One of the following situations could occur:If the hard disk is not empty,
Once the installation starts and all requirements have been fulfilled, YaST2partitions and formats the necessary hard disk space on its own. The entire
2SuSE Adminhost for FirewallNoteRemember the root password very carefully, as you cannot retrieve itlater. This password whenever you perform administ
ContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 Introduction 3SuSE Firewall on CD 2 . . . . . . . . . . . .
resolution, color resolution, and repetition rate frequency are selected for themonitor and a test screen is displayed.NoteCheck the settings before a
2SuSE Adminhost for FirewallFigure 2.4: YaST2: Network ConfigurationConfiguration FilesThis section provides an overview of the network configuration file
Figure 2.5: YaST2: Configuring the Name Serverconsisting of the IP address, the fully qualified host name, and the hostname (e. g., earth) is entered in
2SuSE Adminhost for Firewall## networks This file describes a number of net name-to-address# mappings for the TCP/IP subsystem. It is mostly# used at
An example for /etc/host.conf is shown in File 3.## /etc/host.conf## We have named runningorder hosts bind# Allow multiple addrsmulti on# End of host.
2SuSE Adminhost for FirewallThe “databases” available over NSS are listed in Table 2.2. In addition,automount, bootparams, netmasks, and publickey are
files directly access files, for example, to /etc/aliases.db access via a database.nis NISnisplusdns Only usable by hosts and networks as an exten-sion
2SuSE Adminhost for Firewall# /etc/resolv.conf## Our domainsearch cosmos.com## We use sun (192.168.0.1) as name servername server 192.168.0.1# End of
/etc/init.d/nfsserverStarts the NFS server./etc/init.d/sendmail Controls the sendmail process dependingon the configuration in /etc/rc.config./etc/init
2SuSE Adminhost for FirewallAssign a password for the firewall admin user here. This password must beat least five characters in length. In the next scr
3 Firewall Administration System (FAS) 33Logging in as fwadmin . . . . . . . . . . . . . . . . . . . . . . . . . . . 34Starting the Firewall Administr
Then start the YaST2 Control Center and select ‘Install Patch CD’. Follow theinstructions there.When the installation is finished, restart the FAS daem
3Firewall Administration System (FAS)Firewall AdministrationSystem (FAS)FAS is the graphical administration interface used to create the configurationfl
Logging in as fwadminAfter installation, the system boots to the graphical login. Log in here as theuser fwadmin and use the corresponding password. T
3Firewall Administration System (FAS)Figure 3.2: Creating a New Configurationon CD and, for this reason, is checked for its suitability with the progra
Figure 3.3: Creating a New AccountCreating a New ConfigurationA configuration is created on the inital login. To create additional new con-figurations, s
3Firewall Administration System (FAS)Figure 3.4: Starting a New ConfigurationKernel Runtime Setup (kernel configuration)System Logging (settings for log
SSH Admin Login (login for the administrator with SSH)Time Synchronization (configuration of xntpd to synchronize computertime with a time server)Examp
3Firewall Administration System (FAS)The SetupExample, Inc., an online bookshop with its headquarters in Nuremberg, has150 staff. It operates branches
80.80.80.1. The DNS service is available from the provider under the IPaddresses 123.123.123.123 and 123.123.123.124. The following entrieshave alread
3Firewall Administration System (FAS)Network PoliciesHeads of department in each branch should have full access to the Internet,but all other staff ma
Log File Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99The Log Files . . . . . . . . . . . . . . . . . . . . . . . . . . .
BasicsIn ‘Basics’, either disable the root password completely (default) or set it.As a safety precaution, repeat the root password (see Figure 3.7).
3Firewall Administration System (FAS)Figure 3.8: Configuring the Hard DiskDisk Swap Space: Size of the swap partition, such as 128 MFurther Options Act
Figure 3.9: Network Interfaces1. Make these settings in the ethernet dialog (Figure 3.11 on the facingpage):Interface Names are automatically allocate
3Firewall Administration System (FAS)Figure 3.10: Selecting Network InterfacesFigure 3.11: Ethernet Interface2. The configuration dialog for DSL is div
conf for DSL. This file is involved with the resolution of hostnames by the resolver library and contains the domain of the hostand the IP address of t
3Firewall Administration System (FAS)Figure 3.12: ISDN Configuration — Part 1Interface’s Phone Number (MSN) Enter the phone number of theISDN device (M
Figure 3.13: ISDN Configuration — Part 2RoutingIn a dialog like Figure 3.14 on the next page), view, create, and modifyroutes. ‘Add’ creates a new rout
3Firewall Administration System (FAS)Figure 3.14: Routing DialogNetmask The relevant netmask.Interface Select the interface to use.Save your settings
Figure 3.15: RoutingIn the next entry line, the search lists are specified, for example,your-company-inc.com.If you now click ‘Finish’, the base configu
3Firewall Administration System (FAS)Figure 3.16: Host and Domain ConfigurationOnly entire hard disks can be used. Individual partitions cannot be confi
5 IPsec Client on Windows XP and Windows 2000 131Exporting the Required Certificates . . . . . . . . . . . . . . . . . . . . . 131Importing the Certific
Now the network card (eth1) leading to the DMZ is configured. It shouldbe responsible for a subnet of the public IP addresses. How this subnet ismade a
3Firewall Administration System (FAS)Firewall host name: fw-nbgFirewall domain: example.comAs the name server, the firewall should use the internal DNS
Figure 3.17: IP Forward DialogMasqueradingThe same entry fields are available in ‘Masquerading’ (see Figure 3.18 on thenext page). Masquerading is a sp
3Firewall Administration System (FAS)Figure 3.18: Masquerading DialogDestination Port For ‘From:’, enter the destination port. For ‘To:’, define aserie
Figure 3.19: Dialog for Destination NATSource Address Enter the source IP address.Destination Address Select the destination address.ICMP Select the m
3Firewall Administration System (FAS)Figure 3.20: Dialog for ICMPAddress the internal DNS server from the DMZProtocol UDPLocal address 192.168.8.8/255
POP3 access to the mail server for clients from the internal net-workProtocol TCPLocal address 192.168.10.0/255.255.255.0Remote address 192.168.8.10fr
3Firewall Administration System (FAS)Protocol TCPLocal address 192.168.10.0/255.255.255.192Remote address 0.0.0.0from Port 1to Port 65535Protocol UDPL
Figure 3.21: Kernel Runtime SettingsSystem LoggingIn this dialog, shown in Figure 3.22 on the next page, configure the behav-ior of the Syslog daemon.
3Firewall Administration System (FAS)Figure 3.22: Settings for Syslog Daemonnation for the log files: 192.168.10.254. ‘Enable Log and Traffic Evalua-tio
8 Support, Maintenance, and Patch Management 149Maintenance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149Accessing the SuSE Ma
Figure 3.23: DNS Configurationrules generated automatically and specify the IP addresses of the hosts towrite to the file hosts.allow.The Example, Inc.,
3Firewall Administration System (FAS)Figure 3.24: DNS Access ConfigurationPage 2/2 of the DNS Configuration‘Configure IP filter rules automatically’ must
Figure 3.25: Configuration of the FTP ServerFTP proxy port Port on which the FTP proxy is addressed, normally port21. Viewed from the outside, this tur
3Firewall Administration System (FAS)IP address of the FTP server Enter the IP address of the FTP server locatedin the intranet or in the DMZ.FTP serv
You will not expect many clients to want access to the FTP service at thesame time. To avoid an overloaded line, the maximum number of clientswho can
3Firewall Administration System (FAS)Figure 3.27: Configuration of the Internal FTP ProxyPort reset PASV By default, this check box is activated, so pa
In the second mask, shown in Figure 3.28), configure access to the internalFTP proxy. By default, automatic generation of filter rules is activated. Sel
3Firewall Administration System (FAS)Page 2/2 Internal FTP Proxy ConfigurationIn this module, the filter rules are also generated automatically. The int
Figure 3.29: Configuration of the Generic Proxyand asterisk (‘*’). The wild card ‘?’ stands for any character at all. Aster-isk ‘*’ represents any numb
3Firewall Administration System (FAS)Figure 3.30: Redirect Settings for rinetdThe Example, Inc., ConfigurationGeneric TCP ProxyIn Example, Inc., new sa
Kernel Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . 179Configuration Options in /etc/squid.conf . . . . . . . . . . . . . . 179Squi
allow activatedPattern 80.80.60.*3. IP Filter ConfigurationNo further restrictions need to be made in the “IP Filter Configuration”tab. Only the standar
3Firewall Administration System (FAS)Figure 3.31: Configuration of the External HTTP ProxyThe Example, Inc., ConfigurationPage 1/2 HTTP Proxy — External
Figure 3.32: Access to the External HTTP Proxyto 0.0.0.0/0.0.0.0.Configuring the HTTP Proxy for Internal ConnectionsIn the ‘HTTP Proxy — Internal’ modu
3Firewall Administration System (FAS)Figure 3.33: Configuration of the Internal HTTP ProxyTransparent Proxy Because HTTP requests from clients normally
Figure 3.34: Define ACLsurl_regex Details of URL address using regular expressions.proto (protocol) Specify the appropriate protocol here.src (source)
3Firewall Administration System (FAS)Add Add the new ACL to the list of already created ACLs.Edit If you click ‘Edit’, a window opens in which to ente
Define, via ‘Negate ACL’, an ACL to use in negated form.A new rule is integrated with ‘Add’. It is then be listed in the list fieldof defined ACLs.With t
3Firewall Administration System (FAS)Figure 3.36: Content Filter Dialogallow allows the selected tag/attribute.log creates an entry in the log file, wh
makes sense to enter something else here if you have chosen ‘replcont’,‘replabort’, ‘replskip’, or ‘replendskip’ as the action. Click ‘Add’ to gen-era
3Firewall Administration System (FAS)Figure 3.37: Mime Type FilterEnter the appropriate HTTP port of the provider is entered in ‘Parent ProxyPort’. Re
PrefaceMany thanks to Jürgen Scheiderer, Carsten Höger, Remo Behn, Thomas Biege,Roman Drahtmüller, Marc Heuse, and Stephan Martin.The SuSE Firewall on
Figure 3.38: Configuration of the Internal HTTP ProxyProxy Mode activatedCache activatedMB Cache 1000TipTransparent Proxy and CachingBecause a transpar
3Firewall Administration System (FAS)Figure 3.39: Access to the Internal HTTP ProxyThe values for the ACL are entered by selecting them then editing t
Page 7/7 HTTP Proxy — InternalThe proxy should only be used by clients from the internal network. For thisreason, access is restricted to this network
3Firewall Administration System (FAS)Figure 3.40: Select the Local CertificateGeneral SettingsThis dialog is shown in Figure 3.42 on page 87. Assign a
Figure 3.41: Available CertificatesVPN ConnectionThe ‘VPN connection’ tab is shown in Figure 3.43 on page 88. Under ‘Lo-cal Configuration’, activate the
3Firewall Administration System (FAS)Figure 3.42: VPN: General SettingsA shared key is a random string. Quotation marks (") may not occur in thes
Figure 3.43: VPN ConnectionTo define a rule, first select the transmission protocol: tcp, udp, or icmp. Ifyou select tcp or udp, you only need to specif
3Firewall Administration System (FAS)Figure 3.44: Authentication for a VPN ConnectionWhen satisfied with all the dialogs, click ‘Ok’.Information about
Figure 3.45: Filter Rules for a VPN ConnectionCommon Name RootCAE-mail Address [email protected] unit edvOrganization Example, Inc.Local
3Firewall Administration System (FAS)Figure 3.46: Masquerading for a VPN ConnectionCommon Name Firewall-nbgE-mail Address [email protected]
Comentarios a estos manuales