Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Issues » 2009 » 103 » BEST BEHAVIOR  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

User-level firewalling with Portsmith

BEST BEHAVIOR

Author(s): CHRISTIAN NEY

The Linux packet filter iptables lacks a function that dynamically enables ports for authenticated users. Portsmith plugs this gap, allowing users to enable their own connections.

Check Point and Cisco administrators are familiar with firewalls that enable ports after a user logs in. Unfortunately, this technique, sometimes referred to as Client Authentication or Cut-Through Proxy, is often subject to restrictions. Because of the problems associated with authenticating firewalls, iptables does not include this functionality out of the box. Of course, you could add your own custom authentication feature with some scripting, but few admins go to so much effort.

Portsmith offers a free and easy option for authentication at the firewall, and this innovative tool even lets authenticated users enable ports in their own web browsers. To avoid potential security threats, the administrator still keeps control of the permissions. Each user is assigned a set of required communication links and canonly access the resources assigned to those links. This approach stops users from simply punching holes in the firewall ruleset anytime they feel the urge.


Read full article as PDF »


Comments

OpenBSD's PF still beats IPTables...

John Doe Sep 21, 2009 8:22pm GMT

OpenBSD's PF supports much more and is much better in terms of security, source code, functionality, redundancy, failover, etc.

AuthPF takes care of the authentication and it's freer than Linux's. This is not to shoot down IPTables as some people still use it because they haven't bothered to see the better alternatives yet.

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
THE WAY OF THE RAY Enterprise Collaboration with Liferay
TECH TOOLS
WATCHDOG Better protection with Apache’s ModSecurity module
ASK KLAUS!
ASK KLAUS!
TREND SETTERS Linux New Media Awards 2005
Wherever you go...

...Linux Magazine goes with you!

Check out the advantages of a Digital Subscription:

  • Access articles by downloading PDFs,
  • find the Linux solutions you need with an easy keyword search,
  • maintain your own paperless archive...

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]