07.06.2014 Views

2 - Raspberry PI Community Projects

2 - Raspberry PI Community Projects

2 - Raspberry PI Community Projects

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 14.2<br />

Fwbuilder's main window<br />

fwbuilder can then generate a script configuring the firewall according to the rules that have<br />

been defined. Its modular architecture gives it the ability to generate scripts targeting different<br />

systems (iptables for Linux 2.4/2.6, ipf for FreeBSD and pf for OpenBSD).<br />

Versions of the fwbuilder package since Squeeze contain both the graphical interface and the<br />

modules for each firewall system (these were previously split over several packages, one for<br />

each target system):<br />

# aptitude install fwbuilder<br />

14.2.4. Installing the Rules at Each Boot<br />

If the firewall is meant to protect an intermittent PPP network connection, the simplest way to<br />

deploy the script is to install it as /etc/ppp/ip-up.d/0iptables (note that only files without<br />

a dot in their name are taken into account). The firewall will thus be reloaded every time a PPP<br />

connection is established.<br />

In other cases, the recommended way is to register the configuration script in an up directive<br />

Chapter 14 — Security<br />

381

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!