|
About:
Mason is a tool that interactively builds a firewall using Linux' ipfwadm or ipchains firewalling. You leave mason running on the firewall machine while you are making all the kinds of connections that you want the firewall to support (and want it to block). Mason gives you a list of firewall rules that exactly allow and block those connections. It can either build a firewall from scratch for you or supplement an existing firewall.
Author:
William Stearns [contact developer]
Homepage:
http://www.stearns.org/mason/
RPM package:
http://www.stearns.org/mason/mason-0.13.9.5-1.noarch.rpm
Trove categories:
[change]
Dependencies:
[change]
Shell-Accessible Module Library (required)
[download links]
|
|
» Rating:
(not rated)
» Vitality: 0.00% (Rank 14118)
» Popularity: 0.48% (Rank 12184)

(click to enlarge graphs)
Record hits: 8,275
URL hits: 6,385
Subscribers: 5
|
|
Branches
Releases
Articles referencing this project
Comments
[»]
Use of Mason
by Charlie Peppler - Jan 19th 2000 16:12:26
I had heard about a couple of horror stories about folks hooking a Linux
box up to Mediaone RoadRunner, and knew I needed a firewall. I had an old
Win95 '486 box (24MB RAM, 400MB HD) that I wanted use as the firewall box.
I bought a couple of NIC cards (LNE 2000/Linksys), dropped them in the box,
and loaded RedHat Linux 6.1. After checking a couple of options, I found
Mason. I called Mediaone, changed my MAC address, and brought up Linux on
Mediaone. I set the IP_MASQ rule up, and had access to Mediaone from my
internal LAN through the new (old) '486.
Not wanting the crackers to get in, I started up Mason, and watched it
make a bunch of ipchains rules as I used the various applications from
inside my home LAN. I saw a couple of scans from outside boxes, changed
those rules from ACCEPT to DENY, and set the default rules policy to DENY
on input.
So far, things have been running great. The mason-gui-text user interface
is functional, and works fine on the text console. So far, I've been very
pleased with Mason (developer version 0.13.0.92), and would recommend it to
others. I had heard stories about folks getting their Mediaone access
suspended because of crackers using their open Linux box, so this tool
definitely helps.
[reply]
[top]
|