Staredit Network > Forums > Technology & Computers > Topic: Whitelist Firewall
Whitelist Firewall
Jun 10 2009, 6:27 am
By: Falkoner  

Jun 10 2009, 6:27 am Falkoner Post #1



So, for a summer project a guy I know asked me to set up a completely secure system for him, he's a security software developer and doesn't have time to look heavily into it himself, so he gave me the job.

I have several requests, but the main one is if I can get some advice or suggestions on a good firewall that matches these requirements:
  • Whitelist IP Address Blocking
  • Whitelist Port Blocking
  • Open-Source(I can compile it, perhaps not necessary, but always a plus)
  • Uses a Static Library
  • Freeware
  • Runs on Fedora flavor of the Red Hat flavor of Linux

Now, I'm open to suggestions if anyone knows of a good firewall that matches those, but I also am currently looking into these:

redWall Firewall CD
redWall is a bootable CD-ROM Firewall with Snort, snortsam, dansguardian and support for fwbuilder, spamassassin, reporting (using ACID/sarg/ntop/webfwlog), VPN (FreeSWan/PoPToP/Openvpn) and mail alerting (by mail). Configs are stored on a Floppy or USB


bastion-firewall
bastion-firewall is a Netfilter based firewall for Linux. It can generate graphical stats of all the rules traffic in the firewall with Rrdtool and it's integrated with the Snort Inline IPS. It's written in the bash and C programming languages.


Firestarter
Firestarter is an Open Source visual firewall program. The software aims to combine ease of use with powerful features, therefore serving both Linux desktop users and system administrators.



Not a very long list, so I'm open to any others that you think are good and match those requirements.

Also, I'm testing the security(going through 2 routers with firewalls each, and then to the computer), using other computers, so I'm also open to suggestions on any network security testing or cracking software that you have, currently I'm planning to use:
  • Nmap - I would also appreciate if anyone knows a good front end for it, currently I'm planning on using Zenmap
  • Angry IP Scanner - An awesome utility for basic network scanning
  • Wireshark - I believe this also requires a front end, so any suggestions would be appreciated
  • IP Personality - A OS spoofer, to test if security properly can detect the OS of intruders

Once again, any other good testing software would be appreciated.

Along with the firewalls, all data going in and out of the computer will be recorded using snort, so if you suggest any good front-ends for snort or other add-ons, I would appreciate it, and I'm also looking into an open-source version of tripwire, so if anyone knows where I can find one, please tell.

Thanks in advance.



None.

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[2026-5-04. : 6:44 am]
NudeRaider -- happy star wars day! https://www.youtube.com/watch?v=2SXuVP6mtIk
[2026-4-29. : 2:00 am]
l)ark_ssj9kevin -- hi jamal
[2026-4-29. : 12:18 am]
Heinermann -- memes
[2026-4-28. : 10:08 pm]
NudeRaider -- skeet-skeet, motherfucker
[2026-4-28. : 4:24 pm]
Vrael -- NudeRaider
NudeRaider shouted: Vrael boy, if you're not careful I'll moderate your sorry ass too!
gotta catch me first! skeet skeet skeet
[2026-4-26. : 1:58 pm]
lil-Inferno -- ya
[2026-4-25. : 11:50 pm]
JamaL -- Glad to see SEN will never die. Kudos to whoever is paying the hosting fees these days!
[2026-4-25. : 3:37 pm]
NudeRaider -- (-.-,)
[2026-4-25. : 3:35 pm]
Zoan -- ;o I thought that was a monkey emote
[2026-4-25. : 3:34 pm]
Zoan -- :mods:
Please log in to shout.


Members Online: Rawflesh0615, lil-Inferno, DarkenedFantasies