19.12. Summary

Any system that is directly connected to the Internet is potentially vulnerable to attacks by hackers and other malicious people. After reading this chapter, you should know how to limit the kinds of traffic that your system will accept, making it much harder for attackers to break in. You should also know how to set it up as a masquerading gateway that protects hosts on an internal LAN which still allows them access to the Internet. Finally, you should know how to set up a transparent proxy and configure port forwarding, if required, on your network.

Table 19.2. Module Configuration Options
Directly edit firewall rules instead of save file?Normally, this field is set to No, which tells the module to edit firewall rules in a save file that can be applied by hitting the Apply Configuration button. Selecting Yes switches the module to a different mode, in which all changes are made directly to the active firewall rules. The user interface in this mode is similar, but the apply, revert, and boot-time buttons on the main page are no longer displayed, as they do not make any sense. Directly updating the firewall rules makes sense if some other program on your system is editing them as well, such as PortSentry. However, all rules will be lost when your system is re-booted, unless you have manually created a script to save them at shutdown time with the iptables-save command, and restore them at boot time with iptables-restore.
IPtables save file to editThis field can be used to specify an alternate file for the module to read and update IPtables rules in. You should only change it if your system is using some custom save file, perhaps created by another firewall tool.
Display comment?This field determines if the comment for each rule is shown on the module's main page along with the condition and action.
Display condition?This field determines if each rule's condition is shown on the module's main page.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.190.253.222