1 From mary@home.puzzling.org Fri Apr 22 09:21:41 2005
2 Return-Path: <mary@home.puzzling.org>
3 X-Original-To: courses@linuxchix.org
4 Delivered-To: courses@linuxchix.org
5 Received: from localhost (localhost [127.0.0.1])
6 by www.linuxchix.org (Postfix) with ESMTP id 762CF273113
7 for <courses@linuxchix.org>; Fri, 22 Apr 2005 09:21:41 +1000 (EST)
8 Received: from www.linuxchix.org ([127.0.0.1])
9 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
10 id 07871-07 for <courses@linuxchix.org>;
11 Fri, 22 Apr 2005 09:21:41 +1000 (EST)
12 Received: from smtp.syd.swiftdsl.com.au (smtp.syd.swiftdsl.com.au
14 by www.linuxchix.org (Postfix) with SMTP id 2A316273112
15 for <courses@linuxchix.org>; Fri, 22 Apr 2005 09:21:41 +1000 (EST)
16 Received: (qmail 17536 invoked from network); 21 Apr 2005 23:20:40 -0000
17 Received: from unknown (HELO home.puzzling.org) (218.214.66.203)
18 by smtp.syd.swiftdsl.com.au with SMTP; 21 Apr 2005 23:20:40 -0000
19 Received: from localhost (flay [127.0.0.1])
20 by home.puzzling.org (Postfix) with ESMTP id 837E97880C6
21 for <courses@linuxchix.org>; Fri, 22 Apr 2005 09:20:37 +1000 (EST)
22 Received: from home.puzzling.org ([127.0.0.1])
23 by localhost (flay [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
24 id 24941-10 for <courses@linuxchix.org>;
25 Fri, 22 Apr 2005 09:20:37 +1000 (EST)
26 Received: by home.puzzling.org (Postfix, from userid 1000)
27 id 667A07880C2; Fri, 22 Apr 2005 09:20:37 +1000 (EST)
28 Date: Fri, 22 Apr 2005 09:20:37 +1000
29 From: Mary <mary-linuxchix@puzzling.org>
30 To: courses@linuxchix.org
31 Message-ID: <20050421232037.GB25108@home.puzzling.org>
32 Mail-Followup-To: courses@linuxchix.org
34 Content-Type: text/plain; charset=us-ascii
35 Content-Disposition: inline
36 X-GPG-Key: 1024D/77625870
37 X-GPG-Fingerprint: B141 CD1A 4603 1CD7 6D64 EFBF D256 C568 7762 5870
38 User-Agent: Mutt/1.5.6+20040907i
39 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at home.puzzling.org
40 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at linuxchix.org
41 Subject: [Courses] Call for course: firewall rulesets
42 X-BeenThere: courses@linuxchix.org
43 X-Mailman-Version: 2.1.5
45 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
46 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
47 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
48 List-Archive: <http://linuxchix.org/pipermail/courses>
49 List-Post: <mailto:courses@linuxchix.org>
50 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
51 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
52 <mailto:courses-request@linuxchix.org?subject=subscribe>
53 X-List-Received-Date: Thu, 21 Apr 2005 23:21:41 -0000
59 One of our subscribers suggested that we run a firewall rulesets course
60 where people would exchange firewall rulesets and learn from each other.
62 Is there anyone out there who would be prepared to run such a course?
63 The details of running a course are at
64 http://www.linuxchix.org/content/courses/running_a_course.html
68 PS Please note, this is NOT a promise that the course will run. Like
69 everything on LinuxChix, this will entirely depend on finding volunteers
72 From brat@magma.ca Sat Apr 23 13:58:35 2005
73 Return-Path: <brat@magma.ca>
74 X-Original-To: courses@linuxchix.org
75 Delivered-To: courses@linuxchix.org
76 Received: from localhost (localhost [127.0.0.1])
77 by www.linuxchix.org (Postfix) with ESMTP id 8FBCC273114
78 for <courses@linuxchix.org>; Sat, 23 Apr 2005 13:58:35 +1000 (EST)
79 Received: from www.linuxchix.org ([127.0.0.1])
80 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
81 id 22675-09 for <courses@linuxchix.org>;
82 Sat, 23 Apr 2005 13:58:35 +1000 (EST)
83 Received: from mx2.magma.ca (mx2.magma.ca [206.191.0.250])
84 by www.linuxchix.org (Postfix) with ESMTP id CF6BC27310C
85 for <courses@linuxchix.org>; Sat, 23 Apr 2005 13:58:34 +1000 (EST)
86 Received: from mail4.magma.ca (mail4.magma.ca [206.191.0.222])
87 by mx2.magma.ca (8.13.0/8.13.0) with ESMTP id j3N3wQrf002835
88 for <courses@linuxchix.org>; Fri, 22 Apr 2005 23:58:27 -0400
89 Received: from lemonjelly (ottawa-hs-64-26-176-100.s-ip.magma.ca
91 by mail4.magma.ca (8.13.0/8.13.0) with ESMTP id j3N3wPHM013251
92 for <courses@linuxchix.org>; Fri, 22 Apr 2005 23:58:27 -0400
93 Received: from orchid by lemonjelly with local (Exim 3.35 #1 (Debian))
95 for <courses@linuxchix.org>; Fri, 22 Apr 2005 23:58:23 -0400
96 Date: Fri, 22 Apr 2005 23:58:23 -0400
97 To: courses@linuxchix.org
98 Subject: Re: [Courses] Call for course: firewall rulesets
99 Message-ID: <20050423035823.GA2951@magma.ca>
100 Mail-Followup-To: courses@linuxchix.org
101 References: <20050421232037.GB25108@home.puzzling.org>
103 Content-Type: text/plain; charset=us-ascii
104 Content-Disposition: inline
105 In-Reply-To: <20050421232037.GB25108@home.puzzling.org>
106 User-Agent: Mutt/1.3.28i
107 From: Angelina Carlton <brat@magma.ca>
108 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at linuxchix.org
109 X-BeenThere: courses@linuxchix.org
110 X-Mailman-Version: 2.1.5
112 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
113 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
114 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
115 List-Archive: <http://linuxchix.org/pipermail/courses>
116 List-Post: <mailto:courses@linuxchix.org>
117 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
118 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
119 <mailto:courses-request@linuxchix.org?subject=subscribe>
120 X-List-Received-Date: Sat, 23 Apr 2005 03:58:35 -0000
124 On Fri, Apr 22, 2005 at 09:20:37AM +1000, Mary wrote:
126 > PS Please note, this is NOT a promise that the course will run. Like
127 > everything on LinuxChix, this will entirely depend on finding volunteers
130 I hope there is someone who has the time and inclination to run this
133 I have an iptables script that has now blocked anyone from accessing my
134 webserver and intermittently allows samba traffic accross my
135 network. So yeah...it needs some work.
141 From mary@home.puzzling.org Sat Apr 23 15:36:18 2005
142 Return-Path: <mary@home.puzzling.org>
143 X-Original-To: courses@linuxchix.org
144 Delivered-To: courses@linuxchix.org
145 Received: from localhost (localhost [127.0.0.1])
146 by www.linuxchix.org (Postfix) with ESMTP id CF5C0273114
147 for <courses@linuxchix.org>; Sat, 23 Apr 2005 15:36:18 +1000 (EST)
148 Received: from www.linuxchix.org ([127.0.0.1])
149 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
150 id 23209-06 for <courses@linuxchix.org>;
151 Sat, 23 Apr 2005 15:36:18 +1000 (EST)
152 Received: from smtp.syd.swiftdsl.com.au (smtp.syd.swiftdsl.com.au
154 by www.linuxchix.org (Postfix) with SMTP id 810E32730D3
155 for <courses@linuxchix.org>; Sat, 23 Apr 2005 15:36:18 +1000 (EST)
156 Received: (qmail 21492 invoked from network); 23 Apr 2005 05:35:23 -0000
157 Received: from unknown (HELO home.puzzling.org) (218.214.66.203)
158 by smtp.syd.swiftdsl.com.au with SMTP; 23 Apr 2005 05:35:23 -0000
159 Received: from localhost (flay [127.0.0.1])
160 by home.puzzling.org (Postfix) with ESMTP id 885357880CC
161 for <courses@linuxchix.org>; Sat, 23 Apr 2005 15:35:13 +1000 (EST)
162 Received: from home.puzzling.org ([127.0.0.1])
163 by localhost (flay [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
164 id 00625-09 for <courses@linuxchix.org>;
165 Sat, 23 Apr 2005 15:35:13 +1000 (EST)
166 Received: from sourdust.home.puzzling.org (sourdust.home.puzzling.org
167 [10.0.0.7]) by home.puzzling.org (Postfix) with ESMTP id 6DFB37880CA
168 for <courses@linuxchix.org>; Sat, 23 Apr 2005 15:35:13 +1000 (EST)
169 Received: by sourdust.home.puzzling.org (Postfix, from userid 1000)
170 id 6140835A6D5; Sat, 23 Apr 2005 15:35:12 +1000 (EST)
171 Date: Sat, 23 Apr 2005 15:35:12 +1000
172 From: Mary <mary-linuxchix@puzzling.org>
173 To: courses@linuxchix.org
174 Subject: Re: [Courses] Call for course: firewall rulesets
175 Message-ID: <20050423053512.GB8402@sourdust.home.puzzling.org>
176 Mail-Followup-To: courses@linuxchix.org
177 References: <20050421232037.GB25108@home.puzzling.org>
178 <20050423035823.GA2951@magma.ca>
180 Content-Type: text/plain; charset=us-ascii
181 Content-Disposition: inline
182 In-Reply-To: <20050423035823.GA2951@magma.ca>
183 X-Nihilism: Immortality is all I seek... Give us this day our daily week...
184 X-GPG-Key: 1024D/77625870
185 X-GPG-Fingerprint: B141 CD1A 4603 1CD7 6D64 EFBF D256 C568 7762 5870
186 User-Agent: Mutt/1.5.6+20040907i
187 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at home.puzzling.org
188 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at linuxchix.org
189 X-BeenThere: courses@linuxchix.org
190 X-Mailman-Version: 2.1.5
192 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
193 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
194 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
195 List-Archive: <http://linuxchix.org/pipermail/courses>
196 List-Post: <mailto:courses@linuxchix.org>
197 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
198 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
199 <mailto:courses-request@linuxchix.org?subject=subscribe>
200 X-List-Received-Date: Sat, 23 Apr 2005 05:36:19 -0000
204 On Fri, Apr 22, 2005, Angelina Carlton wrote:
205 > I have an iptables script that has now blocked anyone from accessing
206 > my webserver and intermittently allows samba traffic accross my
207 > network. So yeah...it needs some work.
209 If the course doesn't run (or even if it does) feel free to post the
210 problem to techtalk. Firewalling is on-topic there. It's just that it
211 would only be one thread rather than an entire course.
215 From devdas@dvb.homelinux.org Mon Apr 5 05:54:21 2004
216 Return-Path: <devdas@dvb.homelinux.org>
217 X-Original-To: courses@linuxchix.org
218 Delivered-To: courses@linuxchix.org
219 Received: from localhost (localhost [127.0.0.1])
220 by www.linuxchix.org (Postfix) with ESMTP id 6E0FC272EE9
221 for <courses@linuxchix.org>; Mon, 5 Apr 2004 05:54:21 +1000 (EST)
222 Received: from www.linuxchix.org ([127.0.0.1])
223 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
224 id 05343-05 for <courses@linuxchix.org>;
225 Mon, 5 Apr 2004 05:54:21 +1000 (EST)
226 Received: from tin.nixcartel.org (unknown [66.98.212.93])
227 by www.linuxchix.org (Postfix) with ESMTP id 06437272EA5
228 for <courses@linuxchix.org>; Mon, 5 Apr 2004 05:54:20 +1000 (EST)
229 Received: from dvb.homelinux.org (unknown [202.88.170.34])
230 by tin.nixcartel.org (Postfix) with ESMTP id 99ACB1AC06B
231 for <courses@linuxchix.org>; Sun, 4 Apr 2004 15:17:48 -0500 (CDT)
232 Received: by dvb.homelinux.org (Postfix, from userid 500)
233 id 871AA34022; Mon, 5 Apr 2004 01:23:50 +0530 (IST)
234 Date: Mon, 5 Apr 2004 01:23:50 +0530
235 From: Devdas Bhagat <devdas@dvb.homelinux.org>
236 To: courses@linuxchix.org
237 Message-ID: <20040405012350.C19036@evita.devdas.geek>
239 Content-Type: text/plain; charset=us-ascii
240 Content-Disposition: inline
241 User-Agent: Mutt/1.2.5.1i
242 X-Message-Flag: Friends protect friends from Microsoft
243 X-Virus-Scanned: by amavisd-new-20030616-p7 (Debian) at linuxchix.org
244 Subject: [Courses] [FW] Firewalls course.
245 X-BeenThere: courses@linuxchix.org
246 X-Mailman-Version: 2.1
248 Reply-To: Devdas Bhagat <devdas@dvb.homelinux.org>
249 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
250 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
251 List-Post: <mailto:courses@linuxchix.org>
252 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
253 <mailto:courses-request@linuxchix.org?subject=subscribe>
254 List-Archive: <http://linuxchix.org/pipermail/courses>
255 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
256 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
257 X-List-Received-Date: Sun, 04 Apr 2004 19:54:21 -0000
261 I will be doing a short course on firewalls on this list. Topic [FW].
262 The course would cover:
265 An introduction to security requirements.
266 The TCP/IP stack and basic networking.
268 Stateless and stateful packet filters.
269 Application layer gateways/proxies.
270 Encryption, SSH, IPsec and VPNs.
275 The use/abuse of NAT for security.
276 Apache as a HTTP proxy.
277 Postfix w/ amavisd-new, SA and clamav for email filtering.
281 From yewintsoehtay@bagan.net.mm Mon Apr 5 13:19:33 2004
282 Return-Path: <yewintsoehtay@bagan.net.mm>
283 X-Original-To: courses@linuxchix.org
284 Delivered-To: courses@linuxchix.org
285 Received: from localhost (localhost [127.0.0.1])
286 by www.linuxchix.org (Postfix) with ESMTP id 51533272E77
287 for <courses@linuxchix.org>; Mon, 5 Apr 2004 13:19:33 +1000 (EST)
288 Received: from www.linuxchix.org ([127.0.0.1])
289 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
290 id 11205-07 for <courses@linuxchix.org>;
291 Mon, 5 Apr 2004 13:19:33 +1000 (EST)
292 Received: from localhost.localdomain (unknown [203.81.71.104])
293 by www.linuxchix.org (Postfix) with ESMTP id 237E7272E07
294 for <courses@linuxchix.org>; Mon, 5 Apr 2004 13:19:31 +1000 (EST)
295 Received: from yewintsh (host-1-147.internal.bagan.net.mm [192.168.1.147])
296 by localhost.localdomain (8.12.8/8.11.2) with ESMTP id i353Io4i027012;
297 Mon, 5 Apr 2004 09:49:04 +0630
298 Message-Id: <200404050319.i353Io4i027012@localhost.localdomain>
299 From: "Ye Wint Soe Htay" <yewintsoehtay@bagan.net.mm>
300 To: "'Devdas Bhagat'" <devdas@dvb.homelinux.org>,
301 <courses@linuxchix.org>
302 Subject: RE: [Courses] [FW] Firewalls course.
303 Date: Mon, 5 Apr 2004 09:48:45 +0630
304 Organization: Bagan Cybertech
306 Content-Type: text/plain;
308 Content-Transfer-Encoding: 7bit
309 X-Mailer: Microsoft Office Outlook, Build 11.0.5510
310 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
311 Thread-Index: AcQaft9u+wuqMtqvQouYTCqDFFgXxwAPbyMQ
312 In-Reply-To: <20040405012350.C19036@evita.devdas.geek>
313 X-yoursite-MailScanner-Information: Please contact the ISP for more
315 X-yoursite-MailScanner: Found to be clean
316 X-Virus-Scanned: by amavisd-new-20030616-p7 (Debian) at linuxchix.org
317 X-Topics: Firewalling
318 X-BeenThere: courses@linuxchix.org
319 X-Mailman-Version: 2.1
321 Reply-To: yewintsoehtay@bagan.net.mm
322 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
323 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
324 List-Post: <mailto:courses@linuxchix.org>
325 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
326 <mailto:courses-request@linuxchix.org?subject=subscribe>
327 List-Archive: <http://linuxchix.org/pipermail/courses>
328 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
329 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
330 X-List-Received-Date: Mon, 05 Apr 2004 03:19:33 -0000
336 This is greatly appreciated.
337 I've no or little knowledge in doing FW with Linux.
342 -----Original Message-----
343 From: courses-bounces@linuxchix.org [mailto:courses-bounces@linuxchix.org]
344 On Behalf Of Devdas Bhagat
345 Sent: Monday, April 05, 2004 2:24 AM
346 To: courses@linuxchix.org
347 Subject: [Courses] [FW] Firewalls course.
349 I will be doing a short course on firewalls on this list. Topic [FW].
350 The course would cover:
353 An introduction to security requirements.
354 The TCP/IP stack and basic networking.
356 Stateless and stateful packet filters.
357 Application layer gateways/proxies.
358 Encryption, SSH, IPsec and VPNs.
363 The use/abuse of NAT for security.
364 Apache as a HTTP proxy.
365 Postfix w/ amavisd-new, SA and clamav for email filtering.
369 _______________________________________________
371 Courses@linuxchix.org
372 http://mailman.linuxchix.org/mailman/listinfo/courses
375 From david@aeolia.co.uk Sat Apr 10 21:50:48 2004
376 Return-Path: <david@aeolia.co.uk>
377 X-Original-To: courses@linuxchix.org
378 Delivered-To: courses@linuxchix.org
379 Received: from localhost (localhost [127.0.0.1])
380 by www.linuxchix.org (Postfix) with ESMTP id AD8B1272EE6
381 for <courses@linuxchix.org>; Sat, 10 Apr 2004 21:50:48 +1000 (EST)
382 Received: from www.linuxchix.org ([127.0.0.1])
383 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
384 id 24206-10 for <courses@linuxchix.org>;
385 Sat, 10 Apr 2004 21:50:48 +1000 (EST)
386 Received: from ptb-relay01.plus.net (ptb-relay01.plus.net [212.159.14.212])
387 by www.linuxchix.org (Postfix) with ESMTP id 2AE4C272E8F
388 for <courses@linuxchix.org>; Sat, 10 Apr 2004 21:50:48 +1000 (EST)
389 Received: from [212.159.84.98] (helo=[192.168.0.10])
390 by ptb-relay01.plus.net with esmtp (Exim) id 1BCH0V-0004PP-3t
391 for courses@linuxchix.org; Sat, 10 Apr 2004 11:50:43 +0000
392 Date: Sat, 10 Apr 2004 12:50:42 +0100 (BST)
393 From: David Sumbler <david@aeolia.co.uk>
394 To: courses@linuxchix.org
395 Subject: [Courses] [FW] Firewalls course.
396 Message-ID: <Pine.LNX.4.58.0404101247220.17902@ceres.staly.plus.com>
398 Content-Type: TEXT/PLAIN; charset=US-ASCII
399 X-Virus-Scanned: by amavisd-new-20030616-p7 (Debian) at linuxchix.org
400 X-Topics: Firewalling
401 X-BeenThere: courses@linuxchix.org
402 X-Mailman-Version: 2.1
404 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
405 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
406 List-Post: <mailto:courses@linuxchix.org>
407 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
408 <mailto:courses-request@linuxchix.org?subject=subscribe>
409 List-Archive: <http://linuxchix.org/pipermail/courses>
410 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
411 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
412 X-List-Received-Date: Sat, 10 Apr 2004 11:50:49 -0000
416 I can't wait. This whole subject is one that I have found great
419 I do hope that you will start at a very basic level - then I might be
420 in with a chance of keeping up!
425 From devdas@dvb.homelinux.org Mon Apr 12 10:44:03 2004
426 Return-Path: <devdas@dvb.homelinux.org>
427 X-Original-To: courses@linuxchix.org
428 Delivered-To: courses@linuxchix.org
429 Received: from localhost (localhost [127.0.0.1])
430 by www.linuxchix.org (Postfix) with ESMTP id 6587C272F42
431 for <courses@linuxchix.org>; Mon, 12 Apr 2004 10:44:03 +1000 (EST)
432 Received: from www.linuxchix.org ([127.0.0.1])
433 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
434 id 13127-01 for <courses@linuxchix.org>;
435 Mon, 12 Apr 2004 10:44:03 +1000 (EST)
436 Received: from tin.nixcartel.org (unknown [66.98.212.93])
437 by www.linuxchix.org (Postfix) with ESMTP id B32E9272E92
438 for <courses@linuxchix.org>; Mon, 12 Apr 2004 10:43:58 +1000 (EST)
439 Received: from dvb.homelinux.org (unknown [202.88.170.34])
440 by tin.nixcartel.org (Postfix) with ESMTP id 9EEA71AC06D
441 for <courses@linuxchix.org>; Sun, 11 Apr 2004 19:44:43 -0500 (CDT)
442 Received: by dvb.homelinux.org (Postfix, from userid 500)
443 id 373CD34022; Mon, 12 Apr 2004 06:13:12 +0530 (IST)
444 Date: Mon, 12 Apr 2004 06:13:12 +0530
445 From: Devdas Bhagat <devdas@dvb.homelinux.org>
446 To: courses@linuxchix.org
447 Message-ID: <20040412061311.A21758@evita.devdas.geek>
449 Content-Type: text/plain; charset=us-ascii
450 Content-Disposition: inline
451 User-Agent: Mutt/1.2.5.1i
452 X-Message-Flag: Friends protect friends from Microsoft
453 X-Virus-Scanned: by amavisd-new-20030616-p7 (Debian) at linuxchix.org
454 X-Topics: Firewalling
455 Subject: [Courses] [FW] Starting off.
456 X-BeenThere: courses@linuxchix.org
457 X-Mailman-Version: 2.1
459 Reply-To: Linuxchix courses <courses@linuxchix.org>
460 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
461 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
462 List-Post: <mailto:courses@linuxchix.org>
463 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
464 <mailto:courses-request@linuxchix.org?subject=subscribe>
465 List-Archive: <http://linuxchix.org/pipermail/courses>
466 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
467 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
468 X-List-Received-Date: Mon, 12 Apr 2004 00:44:03 -0000
474 * Please reply to the list with queries, doubts, objections. If you
475 * think I am going too fast, please let me know.
477 Security Requirements
478 =====================
480 This tutorial will comprise of designing and implementing a security
481 infrastructure for a small company.
482 The basic concepts will scale up to an enterprise or down to a single host.
484 We will use the standard 192.0.20.0/24 netblock ( IPv4 documentation subnet,
485 see RFC 3330 ) as the external subnet assigned to this organisation. The
486 company uses the domain name example.com.
491 For the purposes of this tutorial, we will consider a small company
492 with a /24[1] routable netblock[2] from their ISP. The company is dualhomed[3]
493 and announces routes on both their ISPs. The business needs are not complex.
494 The company has a small website, but the primary needs of the Internet
495 connections are email, VPN[4] to their business partners and a limited
496 amount of web surfing. Some business partners insist on authenticating
497 packets, while others are satisfied with just ensuring that the data cannot be
498 read. The company uses a mixture of desktop operating systems internally,
499 primarily Windows 98 and Windows 2000 professional for users and FreeBSD for
500 administrators and they have also recently moved into using wireless with
501 laptops running Windows XP for the sales team. The administrators have remote
502 access via ssh to their desktops.
504 Due to recent news about security incidents, company management has decided to
505 redo their network for security and manageability.
507 Staffing and requirements are:
508 The sales team is 75 people, each having a laptop running Windows XP
510 Senior management is 10 people with Windows 2000 desktops.
511 There are 5 LAN administrators, and 2 people who handle the router and
512 servers all using FreeBSD.
513 There are 3 people in HR and 2 people in the legal department using
514 Windows 2000 professional.
515 3 people in helpdesk running Windows 98.
516 Each person in senior management has a secretary with a desktop running
518 There are 8 teams of 25 people each working on software projects.
519 5 people from each team need to VPN out to various business partners.
520 Each team has one group leader who always has VPN rights. The
521 remaining members of the team VPN out as needed. All these users run
522 Windows 2000 professional.
524 There is one dedicated networked printer between two teams, for a total of 4
526 The secretarial pool shares two printers shared by a windows file share.
527 The remaining people share one networked printer.
529 The network is SNMP supporting switches with a single router at the edge.
530 ===============================================================================
532 This is a fairly simple setup.
533 Currently used systems are:
542 The requirement is to formulate an economically feasible solution for security.
544 ===============================================================================
546 Starting off, we note that there has been no budget formulated for this
547 exercise. There have been no decisions made about what resources need to be
548 protected, and what is the cost of the data and hardware therein. There has
549 also been no decision on the amount of risk acceptable to management for these
551 Hence, there has been no budget allocation for this exercise.
553 The first step is for management to decide what resources are required to be
554 protected and value those resources. A risk analysis must be performed to
555 decide on how much budget should be available to protect each unit.
557 ===============================================================================
559 There is no solution which will offer 100% security to any system.
560 A properly designed and hardened system will be not always sufficent.
561 There is also a need for monitoring this system, upgrading it.
563 A firewall is one small component of a security solution. The security
564 solution must cost less than the resources it is protecting.
566 If the resources being protected are worth 100 USD, buying a 25000 USD
567 safe is not justifiable. If the resources are worth 100000 USD, the
568 25000 USD safe is justified.
570 Tokyo is still vulnerable to attack by giant lizards. The risk of that
571 happening is zero. Fort Knox, on the other hand is a high value, high
572 risk target. The security budget for defending Fort Knox from a would
573 be theif is necessarily much greater than that for protecting Tokyo
576 The budget provided to the security group is necessarily a
577 function of the net worth of resources being protected, and the risk
580 ===============================================================================
581 Once this budgeting is done, then management, administrators and users have to
582 get together and decide on acceptable usage policies(AUP) for the network.
584 This is where the actual work for securing the system starts.
586 Management must support the AUP. If there is no support from management, then
587 the policy is worthless.
588 Users must understand the justification for such policies. Policies cannot be
589 arbitrary. They must allow the users to do their work. They must be explicit
590 about what is allowed, and what is acceptable behaviour.
591 Administrators are responsible for enforcement of these policies. An
592 unenforcable policy is worthless. It is perfectly feasible to make a policy
593 which cannot be enforced at all.
595 ===============================================================================
597 Policies are the basic specifications of the security design.
598 A firewall is the implementation of the security policy on a
600 Without clear, well defined policies, no administrator can implement a
602 http://www.sans.org/ has good example of AUP statements.
604 ==============================================================================
607 1> Create an acceptable usage policy for this scenario.
609 ===============================================================================
610 [1] The /24 is the Classless Inter Domain Routing notation for describing a
611 subnet of 256 IP addresses. To calculate the number of hosts in a subnet /n,
612 number of addresses = 2^(32-n).
613 [2] A routable netblock is one which will be carried by large ISPs globally.
614 This currently stands at a /24.
615 [3] A dual homed system is one which is connected to two different networks.
616 In this case, it means that the company is using two different ISPs
617 simultaneously for access.
618 [4] A VPN is a Virtual Private Network. This is an encrypted IP tunnel riding
619 on top of a regular Internet connection.
621 From ccordova@inictel.gob.pe Sat Apr 24 00:03:59 2004
622 Return-Path: <ccordova@inictel.gob.pe>
623 X-Original-To: courses@linuxchix.org
624 Delivered-To: courses@linuxchix.org
625 Received: from localhost (localhost [127.0.0.1])
626 by www.linuxchix.org (Postfix) with ESMTP id 7B31E273368
627 for <courses@linuxchix.org>; Sat, 24 Apr 2004 00:03:59 +1000 (EST)
628 Received: from www.linuxchix.org ([127.0.0.1])
629 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
630 id 15615-04 for <courses@linuxchix.org>;
631 Sat, 24 Apr 2004 00:03:59 +1000 (EST)
632 Received: from mail.inictel.gob.pe (unknown [64.76.74.206])
633 by www.linuxchix.org (Postfix) with ESMTP id 6547327303D
634 for <courses@linuxchix.org>; Sat, 24 Apr 2004 00:03:51 +1000 (EST)
635 Received: from [192.168.10.34] (unknown [64.76.74.195])
636 by mail.inictel.gob.pe (Postfix) with ESMTP id 46DEDE0395
637 for <courses@linuxchix.org>; Fri, 23 Apr 2004 09:05:06 -0400 (EDT)
638 Subject: Re: [Courses] [FW] Starting off.
639 From: Claudia Cordova Yamauchi <ccordova@inictel.gob.pe>
640 To: Linuxchix courses <courses@linuxchix.org>
641 In-Reply-To: <20040412061311.A21758@evita.devdas.geek>
642 References: <20040412061311.A21758@evita.devdas.geek>
643 Content-Type: text/plain
644 Organization: INICTEL
645 Message-Id: <1082728945.815.0.camel@DTE-ZEPHYR>
647 X-Mailer: Ximian Evolution 1.2.3
648 Date: 23 Apr 2004 09:02:25 -0500
649 Content-Transfer-Encoding: 7bit
650 X-yoursite-MailScanner-Information: Please contact the ISP for more
652 X-yoursite-MailScanner: Found to be clean
653 X-Virus-Scanned: by amavisd-new-20030616-p7 (Debian) at linuxchix.org
654 X-Topics: Firewalling
655 X-BeenThere: courses@linuxchix.org
656 X-Mailman-Version: 2.1
658 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
659 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
660 List-Post: <mailto:courses@linuxchix.org>
661 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
662 <mailto:courses-request@linuxchix.org?subject=subscribe>
663 List-Archive: <http://linuxchix.org/pipermail/courses>
664 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
665 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
666 X-List-Received-Date: Fri, 23 Apr 2004 14:03:59 -0000
670 Thank you very much, this is the course I wanted madly
674 On Sun, 2004-04-11 at 19:43, Devdas Bhagat wrote:
676 > * Please reply to the list with queries, doubts, objections. If you
677 > * think I am going too fast, please let me know.
679 > Security Requirements
680 > =====================
682 > This tutorial will comprise of designing and implementing a security
683 > infrastructure for a small company.
684 > The basic concepts will scale up to an enterprise or down to a single host.
686 > We will use the standard 192.0.20.0/24 netblock ( IPv4 documentation subnet,
687 > see RFC 3330 ) as the external subnet assigned to this organisation. The
688 > company uses the domain name example.com.
692 From ccordova@inictel.gob.pe Thu May 20 01:30:09 2004
693 Return-Path: <ccordova@inictel.gob.pe>
694 X-Original-To: courses@linuxchix.org
695 Delivered-To: courses@linuxchix.org
696 Received: from localhost (localhost [127.0.0.1])
697 by www.linuxchix.org (Postfix) with ESMTP id C1C5B272F2D
698 for <courses@linuxchix.org>; Thu, 20 May 2004 01:30:09 +1000 (EST)
699 Received: from www.linuxchix.org ([127.0.0.1])
700 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
701 id 04070-09 for <courses@linuxchix.org>;
702 Thu, 20 May 2004 01:30:09 +1000 (EST)
703 Received: from mail.inictel.gob.pe (unknown [64.76.74.206])
704 by www.linuxchix.org (Postfix) with ESMTP id E1E2B272EC0
705 for <courses@linuxchix.org>; Thu, 20 May 2004 01:30:08 +1000 (EST)
706 Received: from [192.168.10.35] (unknown [64.76.74.195])
707 by mail.inictel.gob.pe (Postfix) with ESMTP id 28FB0E0B39
708 for <courses@linuxchix.org>; Wed, 19 May 2004 10:32:11 -0400 (EDT)
709 Subject: Re: [Courses] [FW] Starting off.
710 From: Claudia Cordova Yamauchi <ccordova@inictel.gob.pe>
711 To: Linuxchix courses <courses@linuxchix.org>
712 In-Reply-To: <1082728945.815.0.camel@DTE-ZEPHYR>
713 References: <20040412061311.A21758@evita.devdas.geek>
714 <1082728945.815.0.camel@DTE-ZEPHYR>
715 Content-Type: text/plain
716 Organization: INICTEL
717 Message-Id: <1084980551.762.3.camel@DTE-ZEPHYR>
719 X-Mailer: Ximian Evolution 1.2.3
720 Date: 19 May 2004 10:29:11 -0500
721 Content-Transfer-Encoding: 7bit
722 X-yoursite-MailScanner-Information: Please contact the ISP for more
724 X-yoursite-MailScanner: Found to be clean
725 X-Virus-Scanned: by amavisd-new-20030616-p7 (Debian) at linuxchix.org
726 X-Topics: Firewalling
727 X-BeenThere: courses@linuxchix.org
728 X-Mailman-Version: 2.1
730 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
731 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
732 List-Post: <mailto:courses@linuxchix.org>
733 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
734 <mailto:courses-request@linuxchix.org?subject=subscribe>
735 List-Archive: <http://linuxchix.org/pipermail/courses>
736 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
737 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
738 X-List-Received-Date: Wed, 19 May 2004 15:30:10 -0000
744 It is an error with my mailbox or the firewall course is still to begin?
746 On Fri, 2004-04-23 at 09:02, Claudia Cordova Yamauchi wrote:
747 > Thank you very much, this is the course I wanted madly
751 > On Sun, 2004-04-11 at 19:43, Devdas Bhagat wrote:
753 > > * Please reply to the list with queries, doubts, objections. If you
754 > > * think I am going too fast, please let me know.
756 > > Security Requirements
757 > > =====================
759 > > This tutorial will comprise of designing and implementing a security
760 > > infrastructure for a small company.
761 > > The basic concepts will scale up to an enterprise or down to a single host.
763 > > We will use the standard 192.0.20.0/24 netblock ( IPv4 documentation subnet,
764 > > see RFC 3330 ) as the external subnet assigned to this organisation. The
765 > > company uses the domain name example.com.
769 > _______________________________________________
770 > Courses mailing list
771 > Courses@linuxchix.org
772 > http://mailman.linuxchix.org/mailman/listinfo/courses
774 From mary@home.puzzling.org Sat Mar 5 21:22:06 2005
775 Return-Path: <mary@home.puzzling.org>
776 X-Original-To: courses@linuxchix.org
777 Delivered-To: courses@linuxchix.org
778 Received: from localhost (localhost [127.0.0.1])
779 by www.linuxchix.org (Postfix) with ESMTP id 45E2C273030
780 for <courses@linuxchix.org>; Sat, 5 Mar 2005 21:22:06 +1100 (EST)
781 Received: from www.linuxchix.org ([127.0.0.1])
782 by localhost (nest [127.0.0.1]) (amavisd-new, port 10024) with SMTP
783 id 09324-10 for <courses@linuxchix.org>;
784 Sat, 5 Mar 2005 21:22:06 +1100 (EST)
785 Received: from smtp.syd.swiftdsl.com.au (smtp.syd.swiftdsl.com.au
787 by www.linuxchix.org (Postfix) with SMTP id DF47127302E
788 for <courses@linuxchix.org>; Sat, 5 Mar 2005 21:22:05 +1100 (EST)
789 Received: (qmail 29547 invoked from network); 5 Mar 2005 10:21:45 -0000
790 Received: from unknown (HELO home.puzzling.org) (218.214.66.203)
791 by smtp.syd.swiftdsl.com.au with SMTP; 5 Mar 2005 10:21:45 -0000
792 Received: from localhost (flay [127.0.0.1])
793 by home.puzzling.org (Postfix) with ESMTP id 6E0A57880C1
794 for <courses@linuxchix.org>; Sat, 5 Mar 2005 21:21:28 +1100 (EST)
795 Received: from home.puzzling.org ([127.0.0.1])
796 by localhost (flay [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
797 id 04930-08 for <courses@linuxchix.org>;
798 Sat, 5 Mar 2005 21:21:28 +1100 (EST)
799 Received: from sourdust.home.puzzling.org (sourdust.home.puzzling.org
800 [10.0.0.7]) by home.puzzling.org (Postfix) with ESMTP id 5A3A7788078
801 for <courses@linuxchix.org>; Sat, 5 Mar 2005 21:21:28 +1100 (EST)
802 Received: by sourdust.home.puzzling.org (Postfix, from userid 1000)
803 id 0325F35A84E; Sat, 5 Mar 2005 21:21:27 +1100 (EST)
804 Date: Sat, 5 Mar 2005 21:21:27 +1100
805 From: Mary <mary-linuxchix@puzzling.org>
806 To: courses@linuxchix.org
807 Message-ID: <20050305102127.GQ8271@sourdust.home.puzzling.org>
808 Mail-Followup-To: courses@linuxchix.org
810 Content-Type: text/plain; charset=us-ascii
811 Content-Disposition: inline
812 X-Nihilism: Immortality is all I seek... Give us this day our daily week...
813 X-GPG-Key: 1024D/77625870
814 X-GPG-Fingerprint: B141 CD1A 4603 1CD7 6D64 EFBF D256 C568 7762 5870
815 User-Agent: Mutt/1.5.6+20040907i
816 X-Virus-Scanned: by amavisd-new-20030616-p9 (Debian) at home.puzzling.org
817 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at linuxchix.org
818 X-Topics: Firewalling
819 Subject: [Courses] [FW] Firewalling course ended
820 X-BeenThere: courses@linuxchix.org
821 X-Mailman-Version: 2.1.5
823 List-Id: List for courses run by LinuxChix volunteers <courses.linuxchix.org>
824 List-Unsubscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
825 <mailto:courses-request@linuxchix.org?subject=unsubscribe>
826 List-Archive: <http://linuxchix.org/pipermail/courses>
827 List-Post: <mailto:courses@linuxchix.org>
828 List-Help: <mailto:courses-request@linuxchix.org?subject=help>
829 List-Subscribe: <http://mailman.linuxchix.org/mailman/listinfo/courses>,
830 <mailto:courses-request@linuxchix.org?subject=subscribe>
831 X-List-Received-Date: Sat, 05 Mar 2005 10:22:06 -0000
837 The former maintainer of the firewalling course writes that he does not
838 have time to continue the course that he started, at least, not in the
839 foreseeable future. So unfortunately we're going to shut this topic
842 If anyone's interested in running a similar course, please -- you're
843 welcome to. Follow the guidelines at
844 http://www.linuxchix.org/content/courses/running_a_course.html re