Security Basics mailing list archives

Re: Firewall Review


From: Ansgar Wiechers <bugtraq () planetcobalt net>
Date: Fri, 4 May 2012 11:59:03 +0200

He was asking for a tool to review existing rules, though. If you have
to review an existing iptables ruleset, you will have to deal with
iptables syntax I'm afraid.

Regards
Ansgar wiechers

On 2012-05-04 Steve Elkins wrote:
Check out http://www.fwbuilder.org/ 

You create your rules and then output in iptables format (or many others!)


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Thugzclub
Sent: Friday, 4 May 2012 2:08 PM
To: pen-test () securityfocus com
Cc: security-basics () securityfocus com
Subject: Firewall Review

Hi,

I need to review an IPtables rule set  but Iptable syntax is killing me :((. Any guidance on tools that can simplify 
it?


cheers


On 3 May 2012, at 20:12, David Bridgman <David.Bridgman () lifelock com> wrote:

You could get a product like Splunk or setup a Linux box with syslogng and zabbix for the monitoring and logging. 
External companies that monitor firewalls usually create an ssl or vpn connection via the internet to your devices 
to pull in logging information. Depending on what you would like them to do, just logging or config changes you 
will need to give them access for this.

David Bridgman, CISSP
Sr. Information Security Engineer | LifeLock® - Relentlessly 
Protecting Your IdentityT
480.457.2029 Office | 480.253.2633 Cell David.Bridgman () lifelock com
60 E. Rio Salado Parkway, Suite 400, Tempe, AZ 85281



-----Original Message-----
From: listbounce () securityfocus com 
[mailto:listbounce () securityfocus com] On Behalf Of a bv
Sent: Thursday, May 03, 2012 5:25 AM
To: security-basics () securityfocus com
Subject: Firewall availability and reporting

Hi,

Im again in need of  firewall availability and reporting. Is there a solution you can recommend? There are 
companies at web which says we are doing firewall external monitoring but i doent know how do they technically do 
that and how reliable and good working .


Regards

----------------------------------------------------------------------
-- Securing Apache Web Server with thawte Digital Certificate In this 
guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it 
benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4
42f727d1
----------------------------------------------------------------------
--


______________________________________________________________________
_______ The information contained in this transmission may contain 
privileged and confidential information. It is intended only for the use of the person(s) named above. If you are 
not the intended recipient, you are hereby notified that any review, dissemination, distribution or duplication of 
this communication is strictly prohibited. If you are not the intended recipient, please contact the sender by 
reply email and destroy all copies of the original message.
______________________________________________________________________
_______

----------------------------------------------------------------------
-- Securing Apache Web Server with thawte Digital Certificate In this 
guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it 
benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4
42f727d1
----------------------------------------------------------------------
--


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and 
who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell 
if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your 
Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing 
management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: