Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact
Departments


price comparison with idealo.com
Price comparison for:
fast servers for your business solution, fast notebooks for long flights, software for good results, TomTom navigation systems, PC hardware, Plasma and LCD TVs, Computer Hardware and Software, MP3 Player, highend Laptops and many more. Get reviews of your favourite digital camera or  of  new dvd-players.

  linux-magazine.com » Issues » 2006 » 64 » BEYOND THE PORT  

Blocking protocols at Layer 7 with the L7 patch

BEYOND THE PORT

Author(s): JÖRG HARMUTH

If you need a tool for filtering protocols that doesn’t depend on the port, try L7, an IPTables patch that operates through regular expressions.

Traditional firewalls decide whether to allow or reject packets based on IP addresses, TCP flags, MAC addresses, ports, and other criteria that reside in OSI layers two through four. Experienced admins can probably type commands like iptables -A FORWARD -i $IF -o $OF -p tcp --dport 80 --syn -j ACCEPT standing on their heads. But what if the web server listens on port 8500 rather than port 80? Or if a gaming server misuses this port? Peer-to-peer applications are even worse, as there is no way of predicting the ports they will use. And VoIP makes the chaos complete with Real Time Protocol (RTP), which definitely takes liberties when assigning UDP ports.


Read full article as PDF »


Comments


Related Articles
KEEP OUT! Building a dynamic blacklist with Netfilter's Recent module
SINGING Building a Netfilter firewall module
NAME TRACER Insider Tips: Identd with Linux-based Servers
Live Streaming of USENIX Security '08

Can't make it to the 17th USENIX Security Symposium?

No Problem. Just register for the live streaming and follow the tutorials and technical sessions from your own PC. After the live transmission, you can view repeats of the talks, whenever and as often as you like.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2008 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux-Nachrichten] [Linux Events]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Darmowe Programy Poland] [Open Source DVD Poland] [Linux Magazin Romania]
International: [Linux Magazine Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]