`
jimode2013
  • 浏览: 39558 次
社区版块
存档分类
最新评论

Firewall

 
阅读更多

Introduction

Traffic into or out of a computer is filtered through "ports," which are relatively arbitrary designations appended to traffic packets destined for use by a particular application.

By convention, some ports are routinely used for particular types of applications. For example, port 80 is generally used for insecure web browsing and port 443 is used for secure web browsing.

Traffic to particular applications can be allowed or blocked by "opening" or "closing" (i.e. filtering) the ports designated for a particular type of traffic. If port 80 is "closed," for example, no (insecure) web browsing will be possible. The AntiVirus page might also be of interest.

The Linux kernel includes the netfilter subsystem, which is used to manipulate or decide the fate of network traffic headed into or through your computer. All modern Linux firewall solutions use this system for packet filtering.

The kernel's packet filtering system would be of little use to users or administrators without a user interface with which to manage it. This is the purpose of iptables. When a packet reaches your computer, it is handed off to the netfilter subsystem for acceptance, manipulation, or rejection based on the rules supplied to it via iptables. Thus, iptables is all you need to manage your firewall (if you're familiar with it). Many front-ends are available to simplify the task, however.

Users can therefore configure the firewall to allow certain types of network traffic to pass into and out of a system (for instance SSH or web server traffic). This is done by opening and closing TCP and UDP "ports" in the firewall. Additionally, firewalls can be configured to allow or restrict access to specific IP addresses (or IP address ranges). 

 

Managing the Firewall

 

iptables

Iptables is the database of firewall rules and is the actual firewall used in Linux systems. The traditional interface for configuring iptables in Linux systems is the command-line interface terminal. The other utilities in this section simplify the manipulation of the iptables database. 

 

UFW

UFW (Uncomplicated Firewall) is a front-end for iptables and is particularly well-suited for host-based firewalls. UFW was developed specifically for Ubuntu (but is available in other distributions), and is also configured from the terminal. 

Gufw is a graphical front-end to UFW, and is recommended for beginners.

UFW was introduced in Ubuntu 8.04 LTS (Hardy Heron), and is available by default in all Ubuntu installations after 8.04 LTS.

 

Guarddog

Guarddog is a front-end for iptables that functions in KDE-based desktops, such as Kubuntu. It has a greater deal of complexity (and flexibility, perhaps).

 

See Also

Other:

 

External Links

 

分享到:
评论

相关推荐

    WindowsFirewall.diagcab

    当然,如果遇到有 WindowsFirewall.diagcab 无法解决的问题,可以点击查看详细信息来获取相关问题的报告,再到搜索引擎去查找或者咨询 IT Pro。 win10系统如何重置防火墙设置? 如果排查工具没有发现任何错误,可以将...

    Tiny Firewall Pro v6.5.126

    Tiny Software 公司是一家面向中小型网络路由器和防火墙软件的开发商,最近Tiny Firewall目的是为了妨止非法使用时的不安全性,保障计算机的安全。这一版本是基于通过ICSA认证的 WinRoute Pro安全保障技术,是...

    Sygate Personal Firewall V5.5

    Sygate Personal Firewall (以前的Sybergen Secure Desktop)可以让你的系统免遭来自Internet上的非法访问。这个程序功能强大,具伸缩性而且方便安装配置。你可以自由调节安全级别,从全无到最高(几乎不允许任何...

    Windows Firewall Control V5.1.0 最新注册机

    Windows Firewall Control V5.1.0 最新注册机 Windows Firewall Control 简繁体中文注册版是一个由 BiniSoft 开发的非常有用的小工具,为Windows 7、Windows 8用户提供了最简单最直观的防火墙设置使用方法,支持高...

    Linux系统firewall-cmd 命令详解.docx

    Linux 系统 firewall-cmd 命令详解 firewall-cmd 是 firewalld 的字符界面管理工具,firewalld 是 CentOS 7 的一大特性。firewalld 最大的好处有两个:支持动态更新,不用重启服务;第二个就是加入了防火墙的“zone...

    Firewall_App_Blocker_1.7.zip

    Firewall App Blocker 1.7是一款体积小巧,绿色免安装的禁止程序联网工具,可以制定不需要的程序禁止接入到网络,非常方便实用。 Firewall App Blocker 1.7的主要功能就是阻止你指定的应用程序连接网络,而且操作...

    firewall-cmd命令.txt

    3、firewalld防火墙有两个管理工具,命令行工具:firewall-cmd,图型化的管理工具:firewall-config 。也可以直接编辑XML文件(官方不建议使用些方法)。 4、frewall-cmd创建防火墙规则分基本规则与富规则(Rich ...

    Windows Firewall Control 为Windows 7、 8 最直观防火墙设置

    Windows Firewall Control 为Windows 7、 8 最直观防火墙设置 关于设置中文语言界面: 这款软件官方支持简体中文语言,大家安装完成后复制压缩包中Language Files目录下的wfcCN.lng(简体中文)或者wfcTW.lng(繁体...

    禁止应用程序联网工具 Firewall App Blocker

    **Firewall App Blocker:控制应用程序网络访问的强大工具** Firewall App Blocker(FAB)是一款功能强大的系统工具,主要用于阻止或允许特定的应用程序访问网络。在网络安全日益重要的今天,这款软件提供了一种...

    Juniper Firewall HA指南

    Juniper Firewall HA指南

    PC Tools Firewall Plus

    PC Tools Firewall Plus是一款强大并免费的Windows® 系统个人防火墙,防止未经授权的用户从互联网或网络进行入侵,保护您的电脑。Firewall Plus监控连接到网络的应用程序,能防止木马、后门、键盘监控和其他恶意...

    PC Tools Firewall Plus 防火墙软件

    PC Tools Firewall Plus 是一款强大并免费的Windows® 系统个人防火墙,防止未经授权的用户从互联网或网络进行入侵,保护您的电脑。Firewall Plus监控连接到网络的应用程序,能防止木马、后门、键盘监控和其他...

    SpyShelter Firewall 10.0 简繁体中文注册版

    今天给大家发布一个带防火墙的 SpyShelter Firewall 10.0 SpyShelter防火墙捆绑防记录器的安全工具和一个强大的,双向内一个单一的和直观的界面防火墙。其主要目的是为了保护您的计算机免受恶意攻击和数据窃取的...

    Firewall App Blocker(Fab) v1.9

    Firewall App Blocker(Fab) v1.9

    FFS Firewall v1.0 PHP编写的防火墙程序.zip

    FFS Firewall的处理核心仅3KB不到,对整站系统的负担微乎其微。 FFS Firewall一共有两层防御机制: 其一是代理隔绝,可以抵抗由代理服务器发起的攻击请求(绝大部分的CC攻击就是如此),不过需要注意的是,如果您的...

    Laravel开发-firewall

    在Laravel框架中,"Firewall"通常指的是用于保护应用程序不受恶意访问的安全机制。这个机制允许开发者设置IP白名单和黑名单,从而控制哪些IP地址可以访问应用,哪些应该被阻止。下面将详细介绍Laravel开发中的防火墙...

    Firewall Analyzer 安全日志监控与审计平台

    卓豪Firewall Analyzer是一个安全日志监控与审计平台,能够实时将企业网络安全设施(如防火墙、代理服务器、入侵检测/防御系统和等)在运行过程中产生的安全日志和事件以及配置日志汇集到审计中心,进行全网综合安全...

    Juniper Netscreen & ssg firewall

    Juniper Netscreen & SSG Firewall的配置说明(英文版)。

Global site tag (gtag.js) - Google Analytics