Book Image

Configuring IPCop Firewalls: Closing Borders with Open Source

Book Image

Configuring IPCop Firewalls: Closing Borders with Open Source

Overview of this book

IPCop is a powerful, open source, Linux based firewall distribution for primarily Small Office Or Home (SOHO) networks, although it can be used in larger networks. It provides most of the features that you would expect a modern firewall to have, and what is most important is that it sets this all up for you in a highly automated and simplified way. This book is an easy introduction to this popular application. After introducing and explaining the foundations of firewalling and networking and why they're important, the book moves on to cover using IPCop, from installing it, through configuring it, to more advanced features, such as configuring IPCop to work as an IDS, VPN and using it for bandwidth management. While providing necessary theoretical background, the book takes a practical approach, presenting sample configurations for home users, small businesses, and large businesses. The book contains plenty of illustrative examples.
Table of Contents (16 chapters)
Configuring IPCop Firewalls
Credits
About the Authors
About the Reviewers
Preface
7
Virtual Private Networks
11
IPCop Support

Log Analysis Options


Snort, being such a well-used project, has a variety of analysis products available. We will take a quick look at some of the most commonly used products and the features they provide. The IPCop logging system is not entirely adequate for most analysis, and definitely cannot be used to provide reports, which are commonly required whenever there is an intrusion attempt. Many projects have been created in order to analyze and report on these logs. In order to use these tools you may have to configure IPCop to log to a remote syslog server or in some cases you can install and add on to IPCop.

Perl Scripts

One of the easiest install-and-use products for Snort log analysis is the excellent SnortALog. It offers some excellent features, the most useful being the abilities it has for report generation—you can have reports in ASCII, PDF, or HTML format with images represented as GIF, PNG, or JPEG. This makes for excellent reporting as you can be provided with a variety of...