`
jimode2013
  • 浏览: 37799 次
社区版块
存档分类
最新评论

Firewall

 
阅读更多

Introduction

Traffic into or out of a computer is filtered through "ports," which are relatively arbitrary designations appended to traffic packets destined for use by a particular application.

By convention, some ports are routinely used for particular types of applications. For example, port 80 is generally used for insecure web browsing and port 443 is used for secure web browsing.

Traffic to particular applications can be allowed or blocked by "opening" or "closing" (i.e. filtering) the ports designated for a particular type of traffic. If port 80 is "closed," for example, no (insecure) web browsing will be possible. The AntiVirus page might also be of interest.

The Linux kernel includes the netfilter subsystem, which is used to manipulate or decide the fate of network traffic headed into or through your computer. All modern Linux firewall solutions use this system for packet filtering.

The kernel's packet filtering system would be of little use to users or administrators without a user interface with which to manage it. This is the purpose of iptables. When a packet reaches your computer, it is handed off to the netfilter subsystem for acceptance, manipulation, or rejection based on the rules supplied to it via iptables. Thus, iptables is all you need to manage your firewall (if you're familiar with it). Many front-ends are available to simplify the task, however.

Users can therefore configure the firewall to allow certain types of network traffic to pass into and out of a system (for instance SSH or web server traffic). This is done by opening and closing TCP and UDP "ports" in the firewall. Additionally, firewalls can be configured to allow or restrict access to specific IP addresses (or IP address ranges). 

 

Managing the Firewall

 

iptables

Iptables is the database of firewall rules and is the actual firewall used in Linux systems. The traditional interface for configuring iptables in Linux systems is the command-line interface terminal. The other utilities in this section simplify the manipulation of the iptables database. 

 

UFW

UFW (Uncomplicated Firewall) is a front-end for iptables and is particularly well-suited for host-based firewalls. UFW was developed specifically for Ubuntu (but is available in other distributions), and is also configured from the terminal. 

Gufw is a graphical front-end to UFW, and is recommended for beginners.

UFW was introduced in Ubuntu 8.04 LTS (Hardy Heron), and is available by default in all Ubuntu installations after 8.04 LTS.

 

Guarddog

Guarddog is a front-end for iptables that functions in KDE-based desktops, such as Kubuntu. It has a greater deal of complexity (and flexibility, perhaps).

 

See Also

Other:

 

External Links

 

分享到:
评论

相关推荐

    WindowsFirewall.diagcab

    当然,如果遇到有 WindowsFirewall.diagcab 无法解决的问题,可以点击查看详细信息来获取相关问题的报告,再到搜索引擎去查找或者咨询 IT Pro。 win10系统如何重置防火墙设置? 如果排查工具没有发现任何错误,可以将...

    Tiny Firewall Pro v6.5.126

    Tiny Software 公司是一家面向中小型网络路由器和防火墙软件的开发商,最近Tiny Firewall目的是为了妨止非法使用时的不安全性,保障计算机的安全。这一版本是基于通过ICSA认证的 WinRoute Pro安全保障技术,是...

    Sygate Personal Firewall V5.5

    Sygate Personal Firewall (以前的Sybergen Secure Desktop)可以让你的系统免遭来自Internet上的非法访问。这个程序功能强大,具伸缩性而且方便安装配置。你可以自由调节安全级别,从全无到最高(几乎不允许任何...

    Windows Firewall Control V5.1.0 最新注册机

    Windows Firewall Control V5.1.0 最新注册机 Windows Firewall Control 简繁体中文注册版是一个由 BiniSoft 开发的非常有用的小工具,为Windows 7、Windows 8用户提供了最简单最直观的防火墙设置使用方法,支持高...

    firewall-cmd命令.txt

    3、firewalld防火墙有两个管理工具,命令行工具:firewall-cmd,图型化的管理工具:firewall-config 。也可以直接编辑XML文件(官方不建议使用些方法)。 4、frewall-cmd创建防火墙规则分基本规则与富规则(Rich ...

    Windows Firewall Control 为Windows 7、 8 最直观防火墙设置

    Windows Firewall Control 为Windows 7、 8 最直观防火墙设置 关于设置中文语言界面: 这款软件官方支持简体中文语言,大家安装完成后复制压缩包中Language Files目录下的wfcCN.lng(简体中文)或者wfcTW.lng(繁体...

    Juniper Firewall HA指南

    Juniper Firewall HA指南

    PC Tools Firewall Plus

    PC Tools Firewall Plus是一款强大并免费的Windows® 系统个人防火墙,防止未经授权的用户从互联网或网络进行入侵,保护您的电脑。Firewall Plus监控连接到网络的应用程序,能防止木马、后门、键盘监控和其他恶意...

    PC Tools Firewall Plus 防火墙软件

    PC Tools Firewall Plus 是一款强大并免费的Windows® 系统个人防火墙,防止未经授权的用户从互联网或网络进行入侵,保护您的电脑。Firewall Plus监控连接到网络的应用程序,能防止木马、后门、键盘监控和其他...

    SpyShelter Firewall 10.0 简繁体中文注册版

    今天给大家发布一个带防火墙的 SpyShelter Firewall 10.0 SpyShelter防火墙捆绑防记录器的安全工具和一个强大的,双向内一个单一的和直观的界面防火墙。其主要目的是为了保护您的计算机免受恶意攻击和数据窃取的...

    FFS Firewall v1.0 PHP编写的防火墙程序.zip

    FFS Firewall的处理核心仅3KB不到,对整站系统的负担微乎其微。 FFS Firewall一共有两层防御机制: 其一是代理隔绝,可以抵抗由代理服务器发起的攻击请求(绝大部分的CC攻击就是如此),不过需要注意的是,如果您的...

    Juniper Netscreen & ssg firewall

    Juniper Netscreen & SSG Firewall的配置说明(英文版)。

    Firewall_tutorial.pdf

    very good at understanding the firewall technology and is mandetory for the security specialist or security architect. Very popular book.

    Kerio WinRoute Firewall-6.1.1.4Kerio WinRoute Firewall-6.1.1.4

    Kerio WinRoute Firewall-6.1.1.4-2/4

    ISA 2004 防火墙 firewall

    ISA 2004 ISA 2004 firewall 防火墙

    centos7.0配置firewall

    centos7.0配置firewall,开启默认端口,查看端口,修改端口

    Outpost Firewall Pro v9.1.4652.701.1951.zip

    来自俄罗斯的网络安全解决方案!它为您在网络冲浪时提供了全面的安全防护。具有一般防火墙常有的应用程序访问规则控制以及独特的私人信息保护 (防止密码泄露)、... 请选择 Outpost Firewall Pro 作为您的网络守护神!

    Win7关闭windows firewall-Defender-Tablet pc-UAC服务

    一键Win7关闭windows firewall-Defender-Tablet pc-UAC服务

    Easy Firewall 3.59 x64

    软件名称:Easy Firewall 软件版本:3.5.9 Build 20220806 软件类别:系统工具 应用平台:Windows 7/Windows 8/Windows 10 授权形式:免费 Easy Firewall 是一个辅助设置 Windows 防火墙策略的方便快捷的工具。 这...

Global site tag (gtag.js) - Google Analytics