Using linux to protect a DSL connection.

1999-05-04 Thread Doug Thistlethwaite
Hello,

I am about to get a DSL connection for my home.  I have two systems at
my house (debian linux system and a windoze 95).  Both of these systems
are currently connected to a pipeline 50 (ISDN) router and the pipeline
will be replaced by a DSL gateway.  My ISP will give me two fixed  IP
addresses so each system will have it's own unique one.

I asked the ISP about firewall protection and if I needed to protect my
systems.  He had some pretty funny stories about customers who came home
to an empty paper tray because someone decided to use their printer
(network neighborhood) to print a book or two.  His suggestion was to
use the linux system to protect the win95 system -OR- make absolutely
sure the win95 system didn't have any software that allowed outside
access loaded onto it.

Ok, my little home network uses samba to serve my linux drive to the old
win95 system.  I also plan to use it for printers as well.

Now the question:

How should I protect these systems from outside hack attacks?

If I add a second network card to the linux system and set it up as a
firewall, will I still use the ISP assigned IP address or will it be
wasted?

What is the best way to configure the Samba services so it isn't a
security leak via the gateway?

What else should I think / worry about?

Thanks in advance for your time!

Doug Thistlethwaite


Re: Using linux to protect a DSL connection.

1999-05-04 Thread Will Lowe
 How should I protect these systems from outside hack attacks?
Use Bridging
http://metalab.unc.edu/LDP/HOWTO/mini/Bridge.html
http://metalab.unc.edu/LDP/HOWTO/mini/Bridge+Firewall.html
 and IPChains
http://metalab.unc.edu/LDP/HOWTO/IPCHAINS-HOWTO.html
 
 If I add a second network card to the linux system and set it up as a
 firewall, will I still use the ISP assigned IP address or will it be
 wasted?
This is possible.

 What is the best way to configure the Samba services so it isn't a
 security leak via the gateway?
Don't allow SMB to get through your firewall. :)
Will


--
| [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL PROTECTED]   |
|   http://www.cis.udel.edu/~lowe/   |
|PGP Public Key:  http://www.cis.udel.edu/~lowe/index.html#pgpkey|
--
|   You think you're so smart,  but I've seen you naked  |
|  and I'll prob'ly see you naked again ...  |
| --The Barenaked Ladies,  Blame It On Me  |
--