PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Thu Sep 19, 2019 8:31 am

All times are UTC - 5 hours




Post new topic Reply to topic  [ 13 posts ] 
Author Message
 Post subject: Adaptive firewall
PostPosted: Mon Jun 16, 2008 5:24 pm 
Offline
DevNet Master
User avatar

Joined: Wed Jun 27, 2007 9:44 am
Posts: 4313
Location: Sofia, Bulgaria

_________________
There are 10 types of people in this world, those who understand binary and those who don't


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Sun Jul 13, 2008 3:30 am 
Offline
DevNet Master
User avatar

Joined: Wed Jun 27, 2007 9:44 am
Posts: 4313
Location: Sofia, Bulgaria

_________________
There are 10 types of people in this world, those who understand binary and those who don't


Last edited by VladSun on Mon Jul 14, 2008 1:52 am, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Sun Jul 13, 2008 11:35 am 
Offline
DevNet Master
User avatar

Joined: Tue May 24, 2005 6:01 pm
Posts: 3179
Location: UK
iptables confuses the crap out of me. I use firehol and find it very good.


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Mon Jul 14, 2008 2:00 am 
Offline
DevNet Master
User avatar

Joined: Wed Jun 27, 2007 9:44 am
Posts: 4313
Location: Sofia, Bulgaria
:) I love iptables ;)

In fact, firehol is just a wrapper around iptables - it would be easy for you to write firewalls in plain iptables rules.
And I did stress on the adaptiveness of the firewall - that's the important one :)

_________________
There are 10 types of people in this world, those who understand binary and those who don't


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Mon Jul 14, 2008 7:47 pm 
Offline
DevNet Evangelist

Joined: Tue Dec 21, 2004 6:00 pm
Posts: 6267
Location: Winnipeg
Is this for a production server?

My development server sits behind a NAT router so I don't really concern myself about outside attacks, only internal screw ups on my behalf. :P

I'm wondering though if my dedicated server could use this...if it doesn't already have a firewall -- I think it might though.


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Tue Jul 15, 2008 1:15 am 
Offline
DevNet Master
User avatar

Joined: Wed Jun 27, 2007 9:44 am
Posts: 4313
Location: Sofia, Bulgaria

_________________
There are 10 types of people in this world, those who understand binary and those who don't


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Tue Jul 15, 2008 6:56 am 
Offline
DevNet Evangelist

Joined: Tue Dec 21, 2004 6:00 pm
Posts: 6267
Location: Winnipeg
I'm not even remotely familiar with IP tables...everything above is just gibberish for the most part...your firewall certianly doesn' t have the easy feeling interface of ZoneAlarm, does it? :P

I'll re-read your explanation and then go over some articles and see if I can't understand it better and how everything fits togather.

p.s-I do use port forwarding but only for a few minutes a day to let people test my application then I close the ports. :P


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Tue Jul 15, 2008 7:38 am 
Offline
DevNet Master
User avatar

Joined: Wed Jun 27, 2007 9:44 am
Posts: 4313
Location: Sofia, Bulgaria

_________________
There are 10 types of people in this world, those who understand binary and those who don't


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Mon Jul 21, 2008 1:50 pm 
Offline
DevNet Evangelist

Joined: Tue Dec 21, 2004 6:00 pm
Posts: 6267
Location: Winnipeg
Or drop the mouse all togather and have an iris tracking device move the cursor to wherever my eyes are and blinking should click...instead of typing the deivce should just pick up brain signals and over time build an entire vocabularly of words I frequently use and automatically inject them based on heuristics and a artificial intelligence algorithm that keeps getting smarter. :P

Honestly I would love to get rid of the mouse...it slows me down so much in my daily bump and grind...mastering accelerator keys is nice but way to verbose. I've wondered if any kinf o iris tracker exists which I could install on the top of my monitor and move the cursor with my eyes. That would be sweet. If I ever went into computer science for my masters, that would be my thesis. :P


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Wed Aug 25, 2010 3:59 pm 
Offline
Forum Newbie

Joined: Wed Aug 25, 2010 3:49 pm
Posts: 1
Hi VladSun

This is a really neat script - thanks - exactly what I have been after.

However, i dont appear to have ipset available on my machine - is there a way of running without it - it seems to be just making sure that kernel records of currently active ip's in memory are flushed, renamed, etc as part of the firewall - what would be the impact if i just comment out all references to ipset in your script and use the iptables parts only?

(i think to install ipset i would neet to rebuild my kernel, which i would rather avoid at this point in time - i have enough problems to contend with at present without compounding them).

If you are still around, or if anyone else has an idea, your help wuold be very much appreciated.

cheers


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Wed Aug 25, 2010 10:23 pm 
Offline
Forum Contributor

Joined: Sun Sep 09, 2007 6:27 pm
Posts: 282
Another 'thank you' for this posting, and for the detailed explanation.


Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Thu Aug 26, 2010 2:21 pm 
Offline
DevNet Master
User avatar

Joined: Wed Jun 27, 2007 9:44 am
Posts: 4313
Location: Sofia, Bulgaria

_________________
There are 10 types of people in this world, those who understand binary and those who don't


Last edited by VladSun on Thu Aug 26, 2010 2:23 pm, edited 3 times in total.

Top
 Profile  
 
 Post subject: Re: Adaptive firewall
PostPosted: Thu Aug 26, 2010 2:21 pm 
Offline
DevNet Master
User avatar

Joined: Wed Jun 27, 2007 9:44 am
Posts: 4313
Location: Sofia, Bulgaria

_________________
There are 10 types of people in this world, those who understand binary and those who don't


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 13 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group