Book Image

Configuring IPCop Firewalls: Closing Borders with Open Source

Book Image

Configuring IPCop Firewalls: Closing Borders with Open Source

Overview of this book

IPCop is a powerful, open source, Linux based firewall distribution for primarily Small Office Or Home (SOHO) networks, although it can be used in larger networks. It provides most of the features that you would expect a modern firewall to have, and what is most important is that it sets this all up for you in a highly automated and simplified way. This book is an easy introduction to this popular application. After introducing and explaining the foundations of firewalling and networking and why they're important, the book moves on to cover using IPCop, from installing it, through configuring it, to more advanced features, such as configuring IPCop to work as an IDS, VPN and using it for bandwidth management. While providing necessary theoretical background, the book takes a practical approach, presenting sample configurations for home users, small businesses, and large businesses. The book contains plenty of illustrative examples.
Table of Contents (16 chapters)
Configuring IPCop Firewalls
Credits
About the Authors
About the Reviewers
Preface
7
Virtual Private Networks
11
IPCop Support

What to Do Next?


Once you have identified that an incident has occurred, it is important to quickly act on the incident. Although Snort itself provides nothing more than a few ideas on looking further at a specific event, it's the responsibility of the administrator to decide how to handle an event.

In a smaller network a formalized incident response plan isn't always necessary, but it does help in maintaining system security if we have an idea of what to do if subjected to a specific attack. Some good examples would be port scans, denial of service, and exploitation attempts. We can then decide on things like:

  • Do we want to report these?

  • Do we want to analyze other protection systems if they occur?

  • Do we have to notify someone?

Answering a few basic questions like these as you set up your IDS gives the IDS much more value as it becomes part of a valid plan for network protection.