Master iptables with GUI Firewall Builders - Page 2
Firewall BuilderFirewall Builder is a good choice for more complex needs, such as a multi-homed NAT firewall, or a network with multiple firewalls. It is both a firewall builder and a management system. It incorporates RCS (Revision Control System), so you can easily track all versions of your firewall configurations.
(Courtesy Firewall Builder Project)
Firewall Builder has a useful graphical interface that shows current states, rules, and interfaces all across your network. It is SNMP-aware, and includes a Network Discovery Druid for mapping your network. Be sure to get the User Manual .pdf, as it is a lot more useful than the man pages.
Just Say Yes to Firewalls
Every time the subject of firewalls comes up, you can count on two dissenting voices arising:
2. "Software firewalls are lame. Use a hardware firewall."
#1 is theoretically true, but we live in the real world. Things change, mistakes happen, and layered defenses are a standard best practice. And why let your hosts be pummeled and your LAN congested by outside attacks? Head all that crap off at your Internet gateway. Even public services benefit from being firewalled. For example, there's no need to subject your Web server to the endless SSH attacks infesting the Internet- block everything but port TCP 80. Same goes for all of your public services; reduce the load and potential compromises by diverting the junk.
#2 is one of those silly arguments from the Planet Bizarro. There is no magic in a "hardware firewall." All firewalls are a combination of software and hardware. A firewall is effective because it is well-configured. A more accurate question is "is it better to have a standalone, dedicated firewall, or are host-based firewalls good enough?" I prefer a standalone, dedicated box. It reduces the load on the host PC, and it's easier to maintain and secure, because you can jettison all the irrelevant bits. But well-made host-based iptables firewalls are perfectly good, too. So the definitive answer is "whichever you prefer."