Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 1999 > 9906

Linux Firewall and Masquerading:
The IP Chains Concept in Linux 2.2

Terrehon Bowden and Bodo Bauer

Figure 1 | Figure 2 | Listing 1 | Listing 2 | Listing 3 | Listing 4 | Table 1 | Table 2 | Table 3

Among the many challenges resulting from the over-discussed growth of the Internet are the need for more usable local IP addresses and the need for a reasonable balance between security and access to Internet resources. Installing a firewall is one form of protection. The Linux kernel supports packet filtering, which can be used to implement a simple form of a firewall. One way to gain more usable local IP addresses is to implement a technique called masquerading, in which you hide entire networks with unregistered addresses behind one registered address.

This article gives an introduction to the Linux packet filter mechanisms, which can be used to masquerade packets and to build a firewall. SuSE Linux ships with a set of scripts that implement simple firewalling and masquerading techniques using these kernel features. We will discuss how they work and how to configure them. The scripts shipping with SuSE Linux 6.1 work only with kernels of the 2.0 series. The handling of firewall rules changed in kernel version 2.2. This article covers the new scheme used in the 2.2 series kernels.

The Kernel Packet Filter

Linux has supported packet filtering for quite a while. With version 2.2 of the kernel, there is a significant change in the structure of this service. The basic principles remain the same. There are chains of rules against which the IP packets are matched.




MarketPlace

Download Award-Winning Service Desk software, Free
Try Numara FootPrints 9, The ITSM software that Delivers Real Value, Flexibility and Results.

Instant Answers to Your IT & Business Questions
Sign Up & Get Full Access To The Definitive Online Book Collection With SkillSoft's Books24x7�.

BugSplat - Automatic Crash Analysis
Fast online exception analysis. Capture customer crash data online.

Visit Dell� Small and Medium Business Online Store
One Stop to Buy All Your Business IT Solutions. Browse Through Dell's Best Deals Online Now!

Wanna see your ad here?