PMFirewall
Securing Linux has never been easier.

MENU
Pointman.ORG
Download
Mailing-List
Support
 
PMFirewall
Current Release:3/28/00 - Version 1.1.4

Description: PMFirewall is an Ipchains Firewall and Masquerading Configuration Utility for Linux. It was designed to allow a beginner to build a custom firewall with little or no ipchains experience.
Features: This firewall should work for most Workstations, Servers and Dual NIC routers using either a dialup, DSL, Cable or LAN setup. It is restrictive to outside attacks while still being transparent to those inside.
  • Autodetection of the IP Address and Netmask of each interface.
  • Blocking of NetBIOS, NetBUS, Back Orifice and Samba attacks.
  • Protection against IP Spoofing Attacks.
  • Logging of DENY packets.
  • Manipulation of TOS bits of the packet for optomizing transfers. You must have CONFIG_IP_ROUTE_TOS enabled in your kernel for this to be effective.
  • Masquerading support is decided during install.
  • Your own custom rules can be added to the pmfirewall.rules.local file.

Supported OS:
  • At this point it works on virtually every distribution of linux. If you find one with problems, please let me know.

Known Problems:
  • Version 1.1 has an error which will cause masquerading to be enabled even if you choose not to. Please upgrade to the most current version.
  • Version 1.1.2 has a problem with enabling pmfirewall before pcmcia interfaces are activated. Please upgrade.
  • Version 1.1.4: PROBLEM:
    The custom ports opened at the following line of the install are affected.

    "Are there any other ports you wish to open to the outside? (y/N): "

    During the IP specification section if you just hit enter to allow connections from anywhere it will instead only allow connections from your specific subnet. Fix: Edit the pmfirewall.rules.local file by hand and look for the "#CUSTOM" line. Then in each line after that, replace every instance of $OUTERNET with $REMOTENET.


Legal Info: This version of PMFirewall is released under the GPL. Please see the file COPYING included in this distribution for more information.

This file distributed without warranty of any sort. If you get hacked it is your own fault for being stupid enough to put a server on the Internet when you know how unsafe it can be. :-)

Mailing List: The mailing list is used for updates, announcements and general discussions of the project.

NOTE: The mailing list is current offline until further notice.

Support:

Complete Mailing List Archives are located here.

The man page is now available online.


Download: pmfirewall-1.1.4.tar.gz (59KB)

Primary Site HTTP
Primary Site FTP





© Copyright Rick Johnson 2000, All rights reserved. Permission to reproduce the above material in any form (electronic or physical) is forbidden without the authors written consent.
Contact the Author for information.