logo

NORAD Was Blind During Y2k Vigil -- Satellite Redundancy Wasnīt There


Latest News Stories:

cover-eletronicprivacy

Only $31.95

New Methodology:

shun

Product Reviews

OSAll is starting to do weekly product reviews, to be published every single Friday.  Check out software, book and hardware reviews.

 Check it out!

Front | Methods | BBS | FAQ | Adverts | Mail | Write | Link | Shop

"Y2k, all hype, all the time."

TIS FWTK Firewall

Firewalls are a recognized and efficient way of protecting your data from outside attack... One of the more efficient (and least expensive -- itīs free) programs for creating simple firewalls is TIS FWTK, or Trusted Information Systems Firewall Toolkit.  You can get the FWTK from ftp.tis.com

The kit includes proxies for Telnet, FTP, Rlogin, Sendmail, HTTP and the X Windows section.  For each proxy, you need to specify a set of rules by editing three files. 

  • /etc/services
    This file is already on your system, itīs used to decide what services your machine will run and what ports theyīre on.  Youīll use this file to set what ports your proxies will run on.
  • /usr/local/etc/netperm-table
    This is a FWTK file and as such isnīt on your system until you install FWTK (makes sense, right?)  In it, yoiuīll specify who can use the services FWTK will regulate.
  • /etc/inetd.conf
    This fileīs already on your system, too.  Itīs the config file for inetd and specifies what serverīs used when a request is made for a service.  Here youīre going to specify your proxies as replacements for the default servers.

Itīs now time to decide how secure your systemīs going to be.  You can tell FWTK to make services allowed by default or prohibited by default.  In the first case, anyhthing you donīt expressly turn off will be allowed -- in the second, anything you donīt expressly turn off (or on) wonīt be allowed.

To grant or deny access to an FWTK-controlled service, you can create IP masks to allow or disallow users...  You can either disallow specific people or hosts or allow only specific people or hosts.

Because FWTK is an application gateway, any outgoing traffic is going to be proxied as well -- a problem with this kind of firewall.

So go ahead, try out some rules and have fun... This firewall isnīt really suited for a lot of more-used systems out there, but it can be a lot of fun to learn on your own.

Good luck!

Donīt forget to discuss this issue on the OSAll BBSystem!

All content copyright 1998 - 99 unless book covers or otherwise noted.  Book covers copyright 1998 - 99 Amazon.com.  All OSAll-owned content may be reprinted with the following header added: "Copyright 1998 - 99 Owl Services.  Visit aviary-mag.com for computer security news and information."  Article authors retain a non-exclusive right to republish their work.   324