Linux Firewalls: Enhancing Security with nftables and Beyond
Book information
Description
Contents......Page 10 Preface......Page 20 About the Author......Page 22 I: Packet Filtering and Basic Security Measures......Page 24 1 Preliminary Concepts Underlying Packet-Filtering Firewalls......Page 26 The OSI Networking Model......Page 28 The Internet Protocol......Page 30 Transport Mechanisms......Page 37 Don’t Forget Address Resolution Protocol......Page 40 Hostnames and IP Addresses......Page 41 Service Ports: The Door to the Programs on Your System......Page 42 Summary......Page 46 2 Packet-Filtering Concepts......Page 48 A Packet-Filtering Firewall......Page 49 Choosing a Default Packet-Filtering Policy......Page 52 Filtering Incoming Packets......Page 54 Filtering Outgoing Packets......Page 69 Private versus Public Network Services......Page 72 Summary......Page 73 Differences between IPFW and Netfilter Firewall Mechanisms......Page 74 Basic iptables Syntax......Page 77 iptables Features......Page 78 iptables Syntax......Page 84 Summary......Page 105 Basic nftables Syntax......Page 106 nftables Features......Page 107 nftables Syntax......Page 108 Summary......Page 116 5 Building and Installing a Standalone Firewall......Page 118 The Linux Firewall Administration Programs......Page 119 Initializing the Firewall......Page 122 Protecting Services on Assigned Unprivileged Ports......Page 135 Enabling Basic, Required Internet Services......Page 140 Enabling Common TCP Services......Page 145 Enabling Common UDP Services......Page 157 Logging Dropped Outgoing Packets......Page 161 Installing the Firewall......Page 162 Summary......Page 164 II: Advanced Issues, Multiple Firewalls, and Perimeter Networks......Page 166 Rule Organization......Page 168 User-Defined Chains......Page 171 Optimized Examples......Page 174 What Did Optimization Buy?......Page 199 Summary......Page 200 The Limitations of a Standalone Firewall......Page 202 Basic Gateway Firewall Setups......Page 204 LAN Security Issues......Page 205 Configuration Options for a Trusted Home LAN......Page 206 Configuration Options for a Larger or Less Trusted LAN......Page 211 Summary......Page 218 The Conceptual Background of NAT......Page 220 NAT Semantics with iptables and nftables......Page 224 Examples of SNAT and Private LANs......Page 229 Examples of DNAT, LANs, and Proxies......Page 232 Summary......Page 233 General Firewall Development Tips......Page 234 Listing the Firewall Rules......Page 236 Interpreting the System Logs......Page 240 Checking for Open Ports......Page 246 Summary......Page 250 VPN Protocols......Page 252 Linux and VPN Products......Page 255 VPN and Firewalls......Page 256 Summary......Page 257 III: Beyond iptables and nftables......Page 258 Detecting Intrusions......Page 260 Symptoms Suggesting That the System Might Be Compromised......Page 261 What to Do If Your System Is Compromised......Page 264 Incident Reporting......Page 266 Summary......Page 270 Intrusion Detection Toolkit: Network Tools......Page 272 Rootkit Checkers......Page 274 Filesystem Integrity......Page 278 Log Monitoring......Page 279 How to Not Become Compromised......Page 280 Summary......Page 284 Listening to the Ether......Page 286 TCPDump: A Simple Overview......Page 288 Using TCPDump to Capture Specific Protocols......Page 295 Automated Intrusion Monitoring with Snort......Page 309 Monitoring with ARPWatch......Page 314 Summary......Page 316 Filesystem Integrity Defined......Page 318 Installing AIDE......Page 319 Configuring AIDE......Page 320 Monitoring AIDE for Bad Things......Page 324 Cleaning Up the AIDE Database......Page 325 Changing the Output of the AIDE Report......Page 326 Defining Macros in AIDE......Page 329 The Types of AIDE Checks......Page 330 Summary......Page 333 IV: Appendices......Page 334 Security Information Sources......Page 336 Reference Papers and FAQs......Page 337 iptables Firewall for a Standalone System from Chapter 5......Page 338 nftables Firewall for a Standalone System from Chapter 5......Page 351 Optimized iptables Firewall from Chapter 6......Page 355 nftables Firewall from Chapter 6......Page 368 B......Page 374 C......Page 375 E......Page 376 F......Page 377 I......Page 378 N......Page 379 P......Page 380 S......Page 382 T......Page 383 X......Page 384 1. Applicability and Definitions......Page 386 3. Copying in Quantity......Page 388 4. Modifications......Page 389 5. Combining Documents......Page 390 8. Translation......Page 391 10. Future Revisions of this License......Page 392 11. Relicensing......Page 393 A......Page 394 B......Page 395 C......Page 396 D......Page 398 E......Page 399 F......Page 400 G......Page 401 I......Page 402 L......Page 407 M......Page 408 N......Page 409 O......Page 412 P......Page 414 R......Page 416 S......Page 418 T......Page 420 U......Page 422 Z......Page 423
Similar books
Learning DevSecOps: A Practical Guide to Processes and Tools
2024 · PDF
Learning DevSecOps
2024 · EPUB
CompTIA Linux+ Practice Tests: Exam XK0-005, 3rd Edition
2022 · EPUB
CompTIA Linux+ Practice Tests: Exam XK0-005
2022 · EPUB
CompTIA Linux+ Practice Tests: Exam XK0-005
2022 · PDF
Redis for Dummies
2021 · PDF
PHP, MySQL, JavaScript & HTML5 All-in-One For Dummies
2013 · PDF
CompTIA Linux+ and LPIC Practice Tests: Exams LX0-103/LPIC-1 101-400, LX0-104/LPIC-1 102-400, LPIC-2 201, and LPIC-2 202
2017 · AZW3