Staredit Network > Forums > Technology & Computers > Topic: Whitelist Firewall
Whitelist Firewall
Jun 10 2009, 6:27 am
By: Falkoner  

Jun 10 2009, 6:27 am Falkoner Post #1



So, for a summer project a guy I know asked me to set up a completely secure system for him, he's a security software developer and doesn't have time to look heavily into it himself, so he gave me the job.

I have several requests, but the main one is if I can get some advice or suggestions on a good firewall that matches these requirements:
  • Whitelist IP Address Blocking
  • Whitelist Port Blocking
  • Open-Source(I can compile it, perhaps not necessary, but always a plus)
  • Uses a Static Library
  • Freeware
  • Runs on Fedora flavor of the Red Hat flavor of Linux

Now, I'm open to suggestions if anyone knows of a good firewall that matches those, but I also am currently looking into these:

redWall Firewall CD
redWall is a bootable CD-ROM Firewall with Snort, snortsam, dansguardian and support for fwbuilder, spamassassin, reporting (using ACID/sarg/ntop/webfwlog), VPN (FreeSWan/PoPToP/Openvpn) and mail alerting (by mail). Configs are stored on a Floppy or USB


bastion-firewall
bastion-firewall is a Netfilter based firewall for Linux. It can generate graphical stats of all the rules traffic in the firewall with Rrdtool and it's integrated with the Snort Inline IPS. It's written in the bash and C programming languages.


Firestarter
Firestarter is an Open Source visual firewall program. The software aims to combine ease of use with powerful features, therefore serving both Linux desktop users and system administrators.



Not a very long list, so I'm open to any others that you think are good and match those requirements.

Also, I'm testing the security(going through 2 routers with firewalls each, and then to the computer), using other computers, so I'm also open to suggestions on any network security testing or cracking software that you have, currently I'm planning to use:
  • Nmap - I would also appreciate if anyone knows a good front end for it, currently I'm planning on using Zenmap
  • Angry IP Scanner - An awesome utility for basic network scanning
  • Wireshark - I believe this also requires a front end, so any suggestions would be appreciated
  • IP Personality - A OS spoofer, to test if security properly can detect the OS of intruders

Once again, any other good testing software would be appreciated.

Along with the firewalls, all data going in and out of the computer will be recorded using snort, so if you suggest any good front-ends for snort or other add-ons, I would appreciate it, and I'm also looking into an open-source version of tripwire, so if anyone knows where I can find one, please tell.

Thanks in advance.



None.

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[03:25 am]
Symmetry -- the best part is that he perfectly summed up SEN's discord
[03:12 am]
Ultraviolet -- WeirdoX4857
WeirdoX4857 shouted: Nigga how you ask is it still going strong when you get a text every 3 miles per hour or something
Joined: Yesterday, 12:08 pm Last Active: Yesterday, 12:14 pm , truly a glorious 6 minutes.
[03:11 am]
Ultraviolet -- :lol:
[2026-9-29. : 2:43 am]
Symmetry -- I'm doing my best, damn it
[2026-9-28. : 4:46 pm]
Ultraviolet -- @:@
@:@ shouted: this community still going strong?
Still going.. strong is debatable though.
[2026-9-28. : 4:13 pm]
WeirdoX4857 -- I can't believe this is really been around since 2003 but it does look classic and old asf still better than talking to kids on discord ranting about skibidi toilet and sexuality or whatever mental illness is going on in their heads
[2026-9-28. : 4:11 pm]
WeirdoX4857 -- Nigga how you ask is it still going strong when you get a text every 3 miles per hour or something
[2026-9-28. : 4:10 pm]
WeirdoX4857 -- Where is everybody
[2026-9-28. : 1:21 pm]
@:@ -- this community still going strong?
[2026-9-27. : 4:30 pm]
Oh_Man -- yeah, probs
Please log in to shout.


Members Online: Ultraviolet