TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

FireHOL – Linux firewalling and traffic shaping for humans

123 pointsby trizicover 6 years ago

8 comments

Bucephalus355over 6 years ago
We have a couple of servers we can’t move to the cloud for a variety of reasons. In addition, they are running some <i>super</i> legacy applications.<p>Because of this, we’ve really had to focus on OS level security to protect the application (OS is surprisingly Ubuntu 16).<p>Good Linux Security Software:<p>- ModSecurity V3...tough to figure out but so worth it. An incredible L7 Firewall. Immediately provides benefits<p>- UFW...utterly saves you from IPTABLES. Also has some neat brute force protection (ufw limit ssh).<p>- ModEvasive...Apache Module which is great for preventing automated vuln scanners like Burp Suite<p>- ClamAV...antivirus, who knows how effective but is popular<p>- RKHunter...rootkit hunter, hard to tune but can be worth it<p>Biggest benefit we got though was from setting all HTTPS Headers on the web server (there are 7 of them now I think you can set). The latest headers like “Feature-Policy” which can disable Javascript’s access to webcam, microphone, and more have been very useful.
评论 #18635934 未加载
评论 #18634635 未加载
评论 #18634877 未加载
unethical_banover 6 years ago
I&#x27;m mobile, but has this been updated? I used this in college back in 08 and it was much better than iptables but I don&#x27;t know if it&#x27;s kept up with the times.
评论 #18633973 未加载
评论 #18634989 未加载
64738over 6 years ago
Nice to see it posted here, I&#x27;ve been a happy user of FireHOL for a decade, if not more. For a while I was worried it was going to be abandoned, I&#x27;m really glad it wasn&#x27;t.<p>I&#x27;m not a network guy but I was tasked with setting up some servers at a co-lo, including a box to act as the router. FireHOL was a godsend for helping me to setup the rules.<p>I haven&#x27;t tried FireQOS yet, but I really want to play with it.
iammeowover 6 years ago
I use their iplists in pfblocker-ng since 3 years. It&#x27;s incredibly useful, like &quot;let&#x27;s block all traffic from tor exit nodes appeared online in the last 30 days&quot;.
评论 #18634729 未加载
qwerty456127over 6 years ago
Cool! Add application-level rules (like LittleSnitch) and I&#x27;m buying (literally, I don&#x27;t mind paying for such a feature).
评论 #18634206 未加载
bepvteover 6 years ago
ive used fireQOS and it was a lovely tool i highly recommend it.
joelthelionover 6 years ago
Firehole? Weird name...
orastorover 6 years ago
Read this as a firewall <i>for</i> humans. Am disappointed
评论 #18633498 未加载
评论 #18633177 未加载
评论 #18633191 未加载