Skip to main content

LinuxGuruz Netfilter IPTABLES Firewall Page

The Netfilter Project Homepage http://www.netfilter.org

Source Code
Userspace code (tar.bz2) http://www.netfilter.org/files/iptables-1.3.0.tar.bz2

FAQ
Netfilter/Iptables FAQ http://netfilter.samba.org/documentation/FAQ/netfilter-faq.html
Firewall Forensics (What am I seeing?) FAQ http://www.robertgraham.com/pubs/firewall-seen.html
Network Intrusion Detection Systems - IDS http://www.robertgraham.com/pubs/network-intrusion-detection.html
Sniffing (network wiretap, sniffer) FAQ http://www.robertgraham.com/pubs/sniffing-faq.html
Linux IP Masquerade FAQ http://en.tldp.org/HOWTO/IP-Masquerade-HOWTO/
Firewall Admins Guide to Porn FAQ http://www.robertgraham.com/pubs/firewall-pr0n.html
Hacking Lexicon - hacking dictionary http://www.robertgraham.com/pubs/hacking-dict.html
Submit a FAQ Link or URL http://www.linuxguruz.com/iptables/#links

Scripts
Home LAN masquerading http://the-devil.dnsalias.net/home/extremist_MASQ
Home LAN ip6tables http://the-devil.dnsalias.net/home/extremist6
Basic IPv6 FireWall script http://ipv6.klingon.nl/ipv6firewall/
HomeLAN Security v.1.3.1 http://www.unixpages.com/downloads/HomeLANSecurity-1_3_1.txt
Resets iptables to default values http://www.linuxguruz.com/iptables/scripts/rc.flush-iptables.txt
MonMotha's Firewall 2.3.8-pre7 http://monmotha.mplug.org/firewall/firewall/2.3/rc.firewall-2.3.8-pre9
Firewall BASH Script - by Netcat http://the-devil.dnsalias.net/home/extremist
Arno's IPTABLES Firewall Script http://freshmeat.net/projects/iptables-firewall/?topic_id=151
The Wonder Shaper http://lartc.org/wondershaper/
Projectfiles.com Linux Firewall http://projectfiles.com/firewall/
Technion's IPTables Script http://orbital.wiretapped.net/~technion/iptables
Initial SIMPLE IP Firewall http://www.linuxguruz.com/iptables/scripts/rc.firewall.txt
DMZ IP Firewall script http://www.linuxguruz.com/iptables/scripts/rc.DMZ.firewall.txt
DHCP IP Firewall script http://www.linuxguruz.com/iptables/scripts/rc.DHCP.firewall.txt
UTIN Firewall script http://www.linuxguruz.com/iptables/scripts/rc.UTIN.firewall.txt
Linux Firewall and NAT for DSL http://www.ccl.net/cca/software/UNIX/netfilter/
NATting SOHO firewall http://www.linuxguruz.com/iptables/scripts/rc.firewall_002.txt
Simple IPTABLES firewall http://linux.ardynet.com/ipmasq/ipmasq.php3#iptables
IPTABLES masquerading firewall http://www.linuxguruz.com/iptables/scripts/rc.firewall_023.txt
Script for a dual-homed firewall http://www.linuxguruz.com/iptables/scripts/rc.firewall_004.txt
Script for a multi-homed firewall http://www.linuxguruz.com/iptables/scripts/rc.firewall_005.txt
Set up iptables NAT rules http://www.linuxguruz.com/iptables/scripts/rc.firewall_006.txt
Example netfilter setup http://www.linuxguruz.com/iptables/scripts/rc.firewall_007.txt
Packet filtering setup script http://www.linuxguruz.com/iptables/scripts/rc.firewall_008.txt
Very restrictive set of firewall rules http://www.linuxguruz.com/iptables/scripts/rc.firewall_012.txt
Tightly secured firewall for general use http://www.linuxguruz.com/iptables/scripts/rc.firewall_013.txt
Example NAT usage http://www.linuxguruz.com/iptables/scripts/rc.firewall_014.txt
Run a web server inside LAN http://www.linuxguruz.com/iptables/scripts/rc.firewall_016.txt
Configuration with no services supported http://www.linuxguruz.com/iptables/scripts/rc.firewall_017.txt
Script for NAT and more http://www.linuxguruz.com/iptables/scripts/rc.firewall_018.txt
NAT iptables firewall script http://www.sjdjweis.com/linux/proxyarp/rc.firewall.txt
Routing incoming ppp0 http://www.linuxguruz.com/iptables/scripts/rc.firewall_020.txt
Basic Ipchains Firewall Rule Script http://www.linuxguruz.com/iptables/scripts/rc.firewall_021.txt
Common firewall functions http://www.bagley.org/~doug/firewall/firewall.functions.iptables
Script written by Rick Dicaire http://www.linuxguruz.com/iptables/scripts/rc.firewall_022.txt
NAT and blocking all but Port 22 http://www.linuxguruz.com/iptables/scripts/rc.firewall_024.txt
Firebred iptables Script http://void.printf.net/~bredroll/firewall.html
Email us your rc.firewall script or URL iptables@linuxguruz.com

IRC
EfNet IPTABLES IRC Channel JPilot Java IRC Applet - #IPTABLES

Howto
Linux Stateful Firewall & IP Masquerading http://www.puschitz.com/FirewallAndRouters.shtml
Linux IP Masquerade HOWTO http://www.tldp.org/HOWTO/IP-Masquerade-HOWTO/index.html
Linux iptables HOWTO http://www.linuxguruz.com/iptables/howto/iptables-HOWTO.html
Netfilter Extensions HOWTO - Patch-O-Matic http://www.linuxguruz.com/iptables/howto/netfilter-extensions-HOWTO.html
Linux netfilter Hacking HOWTO http://www.linuxguruz.com/iptables/howto/netfilter-hacking-HOWTO.html
Linux ipnatctl HOWTO http://www.linuxguruz.com/iptables/howto/ipnatctl-HOWTO.html
Linux 2.4 NAT HOWTO http://www.netfilter.org/documentation/HOWTO/NAT-HOWTO.html
Linux 2.4 Packet Filtering HOWTO http://www.linuxguruz.com/iptables/howto/packet-filtering-HOWTO.html
Linux Administrator's Security Guide http://www.seifried.org/lasg/
Networking Concepts HOWTO http://www.linuxguruz.com/iptables/howto/networking-concepts-HOWTO.html
Transparent Proxy mini-HOWTO http://en.tldp.org/HOWTO/TransparentProxy.html
Linux 2.4 Advanced Routing HOWTO http://www.linuxguruz.com/iptables/howto/2.4routing.html
Manpage of IPTABLES http://www.linuxguruz.com/iptables/howto/maniptables.html
tinc from behind a masquerading firewall http://tinc.nl.linux.org/examples/masquerading-firewall.html
Linux Performance, Security, and Managability http://www.linuxguruz.com/iptables/howto/TrinityOS/
Stopping Filesharing http://www.oofle.com/filesharing.php
Submit a Howto Link or URL http://www.linuxguruz.com/iptables/#links

Tutorial
Traffic Shaping with Linux http://www.knowplace.org/shaper/
Firewalling with Netfilter/Iptables http://www.knowplace.org/netfilter/index.html
What is the difference between REJECT and DENY? http://logi.cc/linux/reject_or_deny.html
Linux Advanced Routing & Traffic Control http://www.lartc.org
Iptables Tutorial http://iptables-tutorial.frozentux.net/iptables-tutorial.html
Traffic Shaping (QOS and TOS) http://www.docum.org/docum.org/
Filter The Web With squidGuard http://networking.earthweb.com/netos/article/0,,12083_1371241,00.html
Comparison of iptables Automation Tools http://online.securityfocus.com/infocus/1410
LinuxWorld: San Jose August 2000 http://www.linuxguruz.com/iptables/tutorial/tut1/
Set up an gateway for home or office http://www.yolinux.com/TUTORIALS/LinuxTutorialIptablesNetworkGateway.html
Filtering Packets with iptables http://www.unixreview.com/documents/s=1237/urm0103c/0103c.htm
Using iptables http://www.unixreview.com/documents/s=1236/urm0104l/0104l.htm
Netfilter framework in Linux 2.4 http://www.gnumonks.org/papers/netfilter-lk2000/presentation.html
IPtables Connection tracking http://www.sns.ias.edu/~jns/security/iptables/iptables_conntrack.html
Iptables - What is it http://www.sns.ias.edu/~jns/security/iptables/index.html
Linux Kernel 2.4 Firewalling Matures http://www.linuxsecurity.com/feature_stories/kernel-netfilter.html
Network Security With Linux 2.4 http://www.linux-mag.com/2000-01/bestdefense_01.html
Netfilter Log Format http://logi.cc/linux/netfilter-log-format.php3
Netfilter Log Analyzer http://logi.cc/linux/NetfilterLogAnalyzer.php3
Submit a Tutorial or URL http://www.linuxguruz.com/iptables/#links

Tools
Firewall Builder - Multi-platform configuration and management http://www.fwbuilder.org/
NuFW - Authentication of every connection passing IP filter http://www.nufw.org/
fabfw - Firewall-Script built on iptables http://www.realdealz.ch/fabfw_en.php
Ftwall - Block network traffic from P2P client applications http://www.lowth.com/p2pwall/
Bifrost - GUI firewall management interface to iptables http://bifrost.heimdalls.com/
LinWiz - Linux configuration file and scripting Wizards http://www.lowth.com/LinWiz/
Dnsmasq - caching DNS forwarder http://thekelleys.org.uk/dnsmasq/doc.html
FireHOL, the iptables stateful packet filtering firewall builder http://firehol.sourceforge.net/
adcfw-log - firewall logs analyzer/summarizer http://adcfw-log.sourceforge.net/
BullDog - A comprehensive and progressive firewall http://tanaya.net/BullDog/
WallFire: wflogs - firewall log analysis tool http://www.wallfire.org/wflogs/
Ulog-php - a php analyser for netfilter U-log http://www.inl.fr/article.php3?id_article=7
Firewall Tester http://ftester.sourceforge.net
Easy Firewall Generator for IPTables http://easyfwgen.morizot.net/gen/
YAFT's Another Firewall Tool http://sourceforge.net/projects/yaft
PFG for IPTables http://www.thegate.nu/pfg/
IPTables log analyzer http://www.gege.org/iptables/
Turtle Firewall Project http://turtlefirewall.sourceforge.net
TuxFrw - Firewall Automation Tool http://tuxfrw.sourceforge.net/index.html
Shoreline Firewall http://www.shorewall.net/
levy - Perl Firewall Generater http://muse.linuxmafia.org/levy/
gSshield - BASH Shell Script Configurator http://muse.linuxmafia.org/gshield/
Mason - Builds from system traffic http://www.stearns.org/mason/
GIPTables Firewall - IPTABLES Rules Generator http://www.giptables.org
Firewall Builder - GUI Firewall Frontend http://www.fwbuilder.org/index.html
IPMENU - Curses Firewall Frontend http://users.pandora.be/stes/ipmenu.html
Fireparse - Firewall Log Parser http://aaron.marasco.com/linux.html
SATAN - Port Scanner with a Web Interface http://www.ibiblio.org/pub/packages/security/Satan-for-Linux/
Submit a Tools Link or URL http://www.linuxguruz.com/iptables/#links

Network Security Sites
PenguinSecurity http://www.penguinsecurity.net/
Security Wizards http://www.secwiz.com/
WebHostingTalk Technical & Security Issues Page http://www.webhostingtalk.com/forumdisplay.php?forumid=5
Submit a Network Security Site Link or URL http://www.linuxguruz.com/iptables/#links

Comments

Popular posts from this blog

How to Address the Patching Paradox

Analyze your vulnerability response capabilities.  Assess vulnerability detection and patching capabilities to identify vulnerability response issues. Tackle low-hanging fruit first.  Prioritize minor vulnerability response problems and build a comprehensive vulnerability response strategy over time. Eliminate barriers between security and IT teams.  Combine vulnerability and IT configuration data into a single platform to drive collaboration between security and IT teams. Create end-to-end vulnerability response processes.  Develop vulnerability response processes and ensure that security and IT teams have a shared view of these processes. Retain security talent.  Remove internal barriers, optimize day-to-day processes and automate mundane work; by doing so, an organization can create a positive environment for security teams, increase employee satisfaction and boost the likelihood of retaining top security talent. Manual vulnerability response process...

mobile application Security Testing

Apps that enterprises develop themselves (or have developed by outsourcers) must be tested, to ensure they’re not leaking customer data or opening the enterprise to attack It’s cheaper and faster to test apps pre-production than it is after deployment Automated testing of mobile software is faster and more effective than manual testing Mobile applications interact with back-end web servers and services that also need to be tested That’s where AppScan® comes in What customers struggle with: Deploying secure mobile applications – both iOS and Android Static testing of mobile applications for security exposures, prior to deployment Inability to assess security of mobile applications developed by outsourcers Finding resources to test application code Understanding security risks of the mobile application environment Bringing together mobile application testing results with back-end web application and services resu...