Arno's IPTABLES Firewall Script for Linux Publisher's description
from Arno van Amersfoort
Arno's IPTABLES firewall script was initially written because I needed to protect my single-homed Linux machine at work.
Arno's IPTABLES firewall script was initially written because I needed to protect my single-homed Linux machine at work. I wrote it at the time I couldn't find any script that really satisfied my needs except for one that was written by a guy called 'Seven'.
I helped him for several months with the work on his script by suppling patches, reporting bugs etc. In this period I was fortunately also able to master scripting for iptables myself because soon Seven discontinued his work, I never got to even talk to the guy ever again. At that point I decided to continue his work, or actually I started my own branch based on his script.
In the summer of 2002 I finally got an ADSL connection at home. Initially I used the iptables firewall that came with the great ADSL4LINUX-package (http://www.adsl4linux.nl). But it didn't take me long to come to the conclusion that their iptables firewall lacked important features like port-forwarding and flexbility with "trusted hosts" etc.
I also didn't like the fact that I had to use a different firewall for my home machine and the machine at work. This made me decide to use some of the ADSL4LINUX knowledge to implement ADSL support.
By now (about 1 year later as of writing) there are only few remnants left of Seven's original script and many, many, many improvements were applied. One major improvement is the ADSL and NAT support (Check the 'features' page with the specifiations of my firewall). For version 2 (alpha) I plan to completely rewrite to script to make it more flexible and to increase the usability for others.
Here are some key features of "Arno's IPTABLES Firewall Script":
В· Very secure stateful filtering firewall
В· Both kernel 2.4 & 2.6 support
В· It can be used for both single- and multi(eg. dual)-homed boxes
В· Masquerading (NAT) and SNAT support
В· Multiple external (internet) interfaces
В· Support multiroute NAT & SNAT (load balancing over multiple (internet) interfaces)
В· Port forwarding (NAT)
В· Support MAC address filtering
В· Support for DSL/ADSL modems
В· Support for PPPoE, PPPoA and bridging modem setups
В· Support for static and ISP assigned (DHCP) IPs
В· Support for (transparent) proxies
В· Full support for DMZ's and DMZ-2-LAN forwarding. You can also use it to isolate your eg. wireless LAN.
В· (Nmap)(stealth) portscan detection
В· Protection against SYN-flooding (DoS attacks)
В· Protection against ICMP-flooding (DoS attacks)
В· Extensive user-definable logging with rate limiting to prevent log flooding
В· Includes options to optimize your throughput
В· User definable open ports, closed ports, trusted hosts, blocked hosts etc.
В· Log & protection options are both highly customizable
В· Support for custom iptables rules in a seperate file
В· It can be used with chkconfig runlevel system (eg. RedHat/Fedora)
В· Main focus on TCP/UDP/ICMP but additional support for *ALL* IP protocols
В· It works with Freeswan IPSEC (VPN) & SSH Sentinel (http://www.freeswan.org) ( virtual IP's)
В· It works with PoPTop PPTP (http://www.poptop.org)
В· It works with UPnP
В· DRDOS protection/detection (experimental)
В· It's easy to configure
В· And much more.
What's New in This Release:В· This version calls insserv during configure, when available.
В· This is required, for example, on Debian/Ubuntu systems which use dependency-based booting.
В· It fixes MULTICAST jumping, which should be done at the end of EXT_INPUT_CHAIN, not at the beginning, or users won't be able create "normal" rules for it.
В· It updates several plugins.
System Requirements:No special requirements.
Program Release Status: Minor Update
Program Install Support: Install and Uninstall