Linux Firewalls

By Michael Rash
ISBN: 978-1-59327-141-1
Jan. 22, 2008
2 min read
Building a secure networked Linux box? Then you better know your firewalls. While they’re only one aspect of security, firewalls are often the first line of defense. Linux applications like iptables and fwsnort can provide this support in addition to other features like network address translation (NAT). Unfortunately, as with many firewall applications, the arcane can be important. This book does an excellent job of exposing and explaining how a networked Linux system should work. The book is comprehensive and a relatively easy read for anyone familiar with networking, TCP/IP, and Linux. This is not an introduction to any of these, so don’t drop this book on your parents’ coffee table unless one of them knows how to do a lot more than just turning on a PC. The book starts with the basics like iptables, the main routing application that runs on Linux. It then moves into attacks and defenses, covering applications like psad, which is used to check for port scanner attacks. A sizable chunk of the book addresses the snort firewall (fwsnort), an intrusion detection system. These chapters are well-worth reading since snort is not always part of a system installation. The book wraps up with coverage of port knocking and the author’s Single Packet Authorization (SPA) support for fwknop (FireWall KNock OPerator). Encrypted port knocking can be combined with OS fingerprinting to provide a secure mechanism for initiating VPN links across an unsecured network like the Internet. I keep this book within easy reach since I have a number of different Linux systems running in the lab. Since some of the issues involved are so complex, I uncover something new every time I open it.

About the Author

William G. Wong

Senior Content Director - Electronic Design and Microwaves & RF

I am Editor of Electronic Design focusing on embedded, software, and systems. As Senior Content Director, I also manage Microwaves & RF and I work with a great team of editors to provide engineers, programmers, developers and technical managers with interesting and useful articles and videos on a regular basis. Check out our free newsletters to see the latest content.

You can send press releases for new products for possible coverage on the website. I am also interested in receiving contributed articles for publishing on our website. Use our template and send to me along with a signed release form. 

Check out my blog, AltEmbedded on Electronic Design, as well as his latest articles on this site that are listed below. 

You can visit my social media via these links:

I earned a Bachelor of Electrical Engineering at the Georgia Institute of Technology and a Masters in Computer Science from Rutgers University. I still do a bit of programming using everything from C and C++ to Rust and Ada/SPARK. I do a bit of PHP programming for Drupal websites. I have posted a few Drupal modules.  

I still get a hand on software and electronic hardware. Some of this can be found on our Kit Close-Up video series. You can also see me on many of our TechXchange Talk videos. I am interested in a range of projects from robotics to artificial intelligence. 

Sign up for our eNewsletters
Get the latest news and updates

Voice Your Opinion!

To join the conversation, and become an exclusive member of Electronic Design, create an account today!