Many linux distros installs a firewall by default. Mainly IPTABLES.
If you're looking for a Grafical Interface to easy configure your firewall rules in IPTABLES, then those are the main 3 choices:
1- Lokkit (terminal & gnome)
2- Firestarter
3- Guarddog (kde)
4- $ iptables
5- conclusions
--------
1- Lokkit (Terminal & GNOME)
The easiest one.
A wizard will guide you through few questions and will reconfigure IPTables for you.
Lokkit has a console and a gnome version:
data:image/s3,"s3://crabby-images/6f81b/6f81b62c56e062929edef0bc915641ab2cf24528" alt=""
data:image/s3,"s3://crabby-images/7376e/7376e861af8617e943998cf0d27dde8e09735da3" alt=""
The point is that, in case you need more control over the rules, this is not for you!
Here is an explanation guide
Note for Ubuntu users: use Synaptic to install it, then go to
Menu -> applications -> Other -> Lokkit
--------
2- Firestarter
A nice one.
It provides a GUI for configuring rules and settings on IPTables.
Certainly more configurable than Lokkit, and allows to set up 95% of the rules for a normal use needs.
data:image/s3,"s3://crabby-images/98c77/98c7708e07dc690fa22160ab57862156f40d9023" alt=""
data:image/s3,"s3://crabby-images/1f493/1f493daef36e0636bc849e5aacfb55628ca0dbf5" alt=""
- has a log window of "active connection" and "Real time Events" allowing to quickly check what's goin on;
- add a very useful tryicon to open it in a click;
- both inbound and outbound access policy;
- Support for Denial of Service (DoS) attacks;
- stealth ports;
- whitelists and blacklists
- ...
Here the complete feauture list.
--------
3- Guarddog (KDE)
More professional...
If you are looking for something a bit more professional, then go for Guarddog (which is a KDE Gui).
Guarddog goes a bit deeper respect to Firestarter.
The 2 main differenced are
- Guardog doen't have a realtime event viewer (obviously you still can keep realtime infos "tailing" the logs in a terminal window);
- Guardog has more config options (Eg: NAT rules, connection tracking ...);
data:image/s3,"s3://crabby-images/996d5/996d57b38a7af5d23b296e0865970729fd75d2ac" alt=""
data:image/s3,"s3://crabby-images/d1096/d1096b87396fd23cbdd1ea2078a6e30051d27789" alt=""
- for KDE 2 or 3;
- generates scripts for ipchains and/or iptables;
- can create different zones with different policies;
- Import/Export firewall scripts;
- ipchain and iptables support;
- ...
Here the main feautures list
Here a well documented tutorial
--------
4- $ iptables
If you still prefer to do it by yourself, here you can find a nice HOWTO for strarting to learn the IPTABLES commands
--------
Conclusion
Lokkit
if you dont know or don't care too much about the firewall rules, and just want to add a firewall protection to you desktop.
Firestarter
if u want a full control of your firewall, and want to know in realtime what's going in/out and what's been blocked.
Guarddog
if you want a GUI that does almost the same as the $iptables command line, but don't wonna get crazy spending time to write 1 by 1 every single rule with $iptable on a console ... Guarddog will do it for you.
$ iptables
The old way. it controls everything.
But you still have to write everything by hands.
NNN
2 comments:
You did not mention Firewall Builder - http://www.fwbuilder.org. It is lot more flexible than other GUIs and is better suited for complex firewall configurations.
you can also try a SAAS solution for managing iptables -> https://www.efw.io/Forum it can do AWS cloud integration if needed.
Post a Comment