<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ferm &#8211; extremly easy powerful firewall</title>
	<atom:link href="http://www.krzywanski.net/archives/90/feed" rel="self" type="application/rss+xml" />
	<link>http://www.krzywanski.net/archives/90?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=ferm-extremly-easy-powerful-firewall</link>
	<description>Yet Another Geek bLog</description>
	<lastBuildDate>Tue, 01 Jun 2010 11:21:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Artur</title>
		<link>http://www.krzywanski.net/archives/90/comment-page-1#comment-1312</link>
		<dc:creator>Artur</dc:creator>
		<pubDate>Wed, 17 Feb 2010 16:22:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.krzywanski.net/?p=90#comment-1312</guid>
		<description>Might be. I&#039;ve took this bit form Ferm manual ;)</description>
		<content:encoded><![CDATA[<p>Might be. I&#8217;ve took this bit form Ferm manual <img src='http://www.krzywanski.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 3ED</title>
		<link>http://www.krzywanski.net/archives/90/comment-page-1#comment-1311</link>
		<dc:creator>3ED</dc:creator>
		<pubDate>Tue, 16 Feb 2010 21:03:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.krzywanski.net/?p=90#comment-1311</guid>
		<description>If you set &quot;policy drop&quot; do you need add &quot;invalid drop&quot;? Isn&#039;t it automaticly droped anyway? :&gt;</description>
		<content:encoded><![CDATA[<p>If you set &#8220;policy drop&#8221; do you need add &#8220;invalid drop&#8221;? Isn&#8217;t it automaticly droped anyway? :&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cga</title>
		<link>http://www.krzywanski.net/archives/90/comment-page-1#comment-1304</link>
		<dc:creator>cga</dc:creator>
		<pubDate>Sat, 24 Oct 2009 20:54:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.krzywanski.net/?p=90#comment-1304</guid>
		<description>sorry for flooding. my bad. now icp is working. 

ferm kicks asses. man i&#039;m building a firewall with extreme ease.</description>
		<content:encoded><![CDATA[<p>sorry for flooding. my bad. now icp is working. </p>
<p>ferm kicks asses. man i&#8217;m building a firewall with extreme ease.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cga</title>
		<link>http://www.krzywanski.net/archives/90/comment-page-1#comment-1303</link>
		<dc:creator>cga</dc:creator>
		<pubDate>Sat, 24 Oct 2009 20:32:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.krzywanski.net/?p=90#comment-1303</guid>
		<description>oh i forgot: the icmp seems to not work. if i ping my server it does not respond to ping.

--
cga</description>
		<content:encoded><![CDATA[<p>oh i forgot: the icmp seems to not work. if i ping my server it does not respond to ping.</p>
<p>&#8211;<br />
cga</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cga</title>
		<link>http://www.krzywanski.net/archives/90/comment-page-1#comment-1302</link>
		<dc:creator>cga</dc:creator>
		<pubDate>Sat, 24 Oct 2009 20:29:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.krzywanski.net/?p=90#comment-1302</guid>
		<description>hi,

thanks for the fast reply, i figured out a few things in the meanwhile =) 

now i have (thanks to your example config) a quite nice firewall. 

the only one more question is: you define a $DEV_INTERNET but it seems to me that you don&#039;t use it. what&#039;s the point of defining an interface and not using it? 

anyway if i test the config it says it&#039;s ok and shows teh rules. even iptables -L does it right. is only that i don&#039;t understand this &quot;misconfiguration&quot;

please
thanks

--
cga</description>
		<content:encoded><![CDATA[<p>hi,</p>
<p>thanks for the fast reply, i figured out a few things in the meanwhile =) </p>
<p>now i have (thanks to your example config) a quite nice firewall. </p>
<p>the only one more question is: you define a $DEV_INTERNET but it seems to me that you don&#8217;t use it. what&#8217;s the point of defining an interface and not using it? </p>
<p>anyway if i test the config it says it&#8217;s ok and shows teh rules. even iptables -L does it right. is only that i don&#8217;t understand this &#8220;misconfiguration&#8221;</p>
<p>please<br />
thanks</p>
<p>&#8211;<br />
cga</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Artur</title>
		<link>http://www.krzywanski.net/archives/90/comment-page-1#comment-1301</link>
		<dc:creator>Artur</dc:creator>
		<pubDate>Sat, 24 Oct 2009 18:39:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.krzywanski.net/?p=90#comment-1301</guid>
		<description>Hi,

Try without the second line.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Try without the second line.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cga</title>
		<link>http://www.krzywanski.net/archives/90/comment-page-1#comment-1300</link>
		<dc:creator>cga</dc:creator>
		<pubDate>Sat, 24 Oct 2009 18:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.krzywanski.net/?p=90#comment-1300</guid>
		<description>hi,

first things first: nice article.

i&#039;m starting to use ferm since i want a firewall and a powerful easy setup tool for it.

ferm really rocks but i don&#039;t know it very much yet. i&#039;ve just started using it a googleing for what i need to know. that&#039;s how i &quot;stumbled&quot; upon your blog. 

i&#039;m trying to enable ssh on a certain port (let&#039;s say 10000) , here&#039;s what i&#039;m trying:

         # allow SSH connections
         proto tcp dport 10000 ACCEPT;
         proto (ssh) ACCEPT;

but if i test it i get:

ferm -n -l /etc/ferm/ferm.conf 

[...]
-A INPUT --protocol tcp --dport 10000 --jump ACCEPT
-A INPUT --protocol ssh --jump ACCEPT
[...]

from what i can see and understand, that would accept incoming to port 10000 but also on ssh (which defaults to 22).

what i&#039;d like to achieve is to have only port 10000 and not 22 enabled since my sshd_config has port 10000 set and i don&#039;t want more ports open than the ones i need.

can you help me please?
thanks

--
cga</description>
		<content:encoded><![CDATA[<p>hi,</p>
<p>first things first: nice article.</p>
<p>i&#8217;m starting to use ferm since i want a firewall and a powerful easy setup tool for it.</p>
<p>ferm really rocks but i don&#8217;t know it very much yet. i&#8217;ve just started using it a googleing for what i need to know. that&#8217;s how i &#8220;stumbled&#8221; upon your blog. </p>
<p>i&#8217;m trying to enable ssh on a certain port (let&#8217;s say 10000) , here&#8217;s what i&#8217;m trying:</p>
<p>         # allow SSH connections<br />
         proto tcp dport 10000 ACCEPT;<br />
         proto (ssh) ACCEPT;</p>
<p>but if i test it i get:</p>
<p>ferm -n -l /etc/ferm/ferm.conf </p>
<p>[...]<br />
-A INPUT &#8211;protocol tcp &#8211;dport 10000 &#8211;jump ACCEPT<br />
-A INPUT &#8211;protocol ssh &#8211;jump ACCEPT<br />
[...]</p>
<p>from what i can see and understand, that would accept incoming to port 10000 but also on ssh (which defaults to 22).</p>
<p>what i&#8217;d like to achieve is to have only port 10000 and not 22 enabled since my sshd_config has port 10000 set and i don&#8217;t want more ports open than the ones i need.</p>
<p>can you help me please?<br />
thanks</p>
<p>&#8211;<br />
cga</p>
]]></content:encoded>
	</item>
</channel>
</rss>
