Newie questions about security
- From: "Javier Viegas" <javiercviegas@xxxxxxxxx>
- Date: Wed, 28 Feb 2007 11:41:54 -0300
On 28 Feb 2007 05:38:27 -0800, Jordi <acero_64@xxxxxxxxx> wrote:
Hi,
Hello,
I just managed to configure my server and router and ips yesterday and
now I have questions about security. I did a scan of ports and saw the
only open are the ones I opened. I also set my router firewall to
"standard".
1) Must I CLOSE the ports that I don't use? Or just let them not
forwaded? (they appeared as STEALTH in the ports scan)
2) Should I use an extra firewall in my server plus the one that my
router has ? What about Firestarter? Any other good GPL firewall?
3) Should I adjust the firewall in my router to something custom, not
standard, and what do you recommend me?
4) I fear intruders and specially ddos. I saw a IDS called Snort that
many people use. What do you think? Any other good GPL IDS?
5) Now that I have the server running, y suppose I must stop using
gksudo and use only sudo. Not?
Thanks for your answers.
Jordi
--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact
listmaster@xxxxxxxxxxxxxxxx
Personally, i use shorewall firewall (it can be downloaded with apt) and i
find it really good, it is also well documented and you can always find help
at the mailinglist. Check it out, http://www.shorewall.net/
I really have little experience in this, so i ´ve never used any kind of
IDS. As for the unused ports, in every site of security, it is shown as a
good practice to close all ports unused to reduce the system vulnerability
and only open the ones that are strictly necessary, i agree with these
practice too.
Hope it hepls.
Javier
- References:
- Newie questions about security
- From: Jordi
- Newie questions about security
- Prev by Date: Re: REALLY OT: News Flash
- Next by Date: Re: ssh
- Previous by thread: Re: Newie questions about security
- Next by thread: Re: Newie questions about security
- Index(es):
Relevant Pages
- Re: Cannot connect to RWW from home PC
... That would be the address you need a DNS record for. ... You say "And in the
router you need to forward to your external nic IP" ... Still can't telnet to any of your
ports at your public ip address. ... Heres' the info for our server: ...
(microsoft.public.windows.server.sbs) - Re: What is broken:McAfeee firewall or my router ????? Urgent, ple
... your computer regardless of what McAfee firewall said. ... If your router
is ... warned about those ports being available right away if you had any of those ...
(microsoft.public.security) - Re: What is broken:McAfeee firewall or my router ????? Urgent, ple
... your computer regardless of what McAfee firewall said. ... If your router
is ... warned about those ports being available right away if you had any of those ...
(microsoft.public.security) - Re: loss of SOME connectivity
... I "think" it is DNS. ... Yes, I can ping the router, AND the ISP DNS.
... I cannot connect the inet cable directly to the server because the inet is ...
MS firewall not started. ... (microsoft.public.windows.server.sbs) - Re: IP Addressing
... Address of the ISA server? ... firewall and router). ... On the
firewall create a static NAT entry as I wrote ... (comp.dcom.sys.cisco)