Staredit Network > Forums > Technology & Computers > Topic: Whitelist Firewall
Whitelist Firewall
Jun 10 2009, 6:27 am
By: Falkoner  

Jun 10 2009, 6:27 am Falkoner Post #1



So, for a summer project a guy I know asked me to set up a completely secure system for him, he's a security software developer and doesn't have time to look heavily into it himself, so he gave me the job.

I have several requests, but the main one is if I can get some advice or suggestions on a good firewall that matches these requirements:
  • Whitelist IP Address Blocking
  • Whitelist Port Blocking
  • Open-Source(I can compile it, perhaps not necessary, but always a plus)
  • Uses a Static Library
  • Freeware
  • Runs on Fedora flavor of the Red Hat flavor of Linux

Now, I'm open to suggestions if anyone knows of a good firewall that matches those, but I also am currently looking into these:

redWall Firewall CD
redWall is a bootable CD-ROM Firewall with Snort, snortsam, dansguardian and support for fwbuilder, spamassassin, reporting (using ACID/sarg/ntop/webfwlog), VPN (FreeSWan/PoPToP/Openvpn) and mail alerting (by mail). Configs are stored on a Floppy or USB


bastion-firewall
bastion-firewall is a Netfilter based firewall for Linux. It can generate graphical stats of all the rules traffic in the firewall with Rrdtool and it's integrated with the Snort Inline IPS. It's written in the bash and C programming languages.


Firestarter
Firestarter is an Open Source visual firewall program. The software aims to combine ease of use with powerful features, therefore serving both Linux desktop users and system administrators.



Not a very long list, so I'm open to any others that you think are good and match those requirements.

Also, I'm testing the security(going through 2 routers with firewalls each, and then to the computer), using other computers, so I'm also open to suggestions on any network security testing or cracking software that you have, currently I'm planning to use:
  • Nmap - I would also appreciate if anyone knows a good front end for it, currently I'm planning on using Zenmap
  • Angry IP Scanner - An awesome utility for basic network scanning
  • Wireshark - I believe this also requires a front end, so any suggestions would be appreciated
  • IP Personality - A OS spoofer, to test if security properly can detect the OS of intruders

Once again, any other good testing software would be appreciated.

Along with the firewalls, all data going in and out of the computer will be recorded using snort, so if you suggest any good front-ends for snort or other add-ons, I would appreciate it, and I'm also looking into an open-source version of tripwire, so if anyone knows where I can find one, please tell.

Thanks in advance.



None.

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[03:29 am]
DarkenedFantasies -- Probably just didn't care. For example, at some point before release, they've updated the graphics of some of the Protoss buildings (Forge, CyberCore, Citadel, Observatory, Arbiter Tribunal), but instead of properly re-rendering them with edited 3D models, they did crappy copy-paste jobs on the rendered graphics.
[08:35 pm]
Ultraviolet -- :wob:
[2026-6-21. : 11:38 pm]
Symmetry -- :wob:
[2026-6-21. : 4:56 am]
Ultraviolet -- I suppose we'll likely never know, but my guess would be that they already saw it operating successfully and there was no monetary incentive to finish the original work. And the dev cycle in old school Blizzard was so hectic, it's possible it just got forgotten about after the original game got released. Plus there's an element of existing MPQ files that were packaged with the original discs becoming outdated if they updated it. And it's not like they remade the original MPQs, they just made new ones for BW specifically
[2026-6-21. : 4:26 am]
Oh_Man -- so that makes me think maybe the theory they are unfinished is not true and its a deliberate design decision, coz why not finish them wen ur making brood war?
[2026-6-21. : 4:25 am]
Oh_Man -- the thing is thos buildings are from classic. that means they went ahead and made brood war without ever finishing the 'unfinished' buildings
[2026-6-20. : 6:15 pm]
Ultraviolet -- Yeah he's talked about a lot of that stuff in his casts before. It seems plausible. Especially knowing how Blizzard of yesteryear operated.
[2026-6-20. : 3:47 pm]
NudeRaider -- to clarify: couldn't recall the behavior for every single Protoss building but I was aware the disparity exists.
[2026-6-20. : 3:43 pm]
NudeRaider -- Contained nothing new for me. Didn't know all building's behavior, but very much all unit's. Also Terran balance whine - also nothing new :lol:
[2026-6-19. : 9:57 am]
Oh_Man -- makes me wonder if SEN knows anything about the topic
Please log in to shout.


Members Online: Roy