3. Securing your Internet Access via DrakFirewall

This little tool allows you to set up a basic firewall on your machine. It filters connection attempts made from the outside, and blocks unauthorized ones. It's a good idea to run it just after installing your machine and before connecting to the Internet, therefore minimizing the risks of your machine being compromised.

This Wizard consists of the steps we detail below.

3.1. Choosing Services to be Available from Outside

Figure 7.5. The DrakFirewall Window

The DrakFirewall Window

Open Up Ports, If Needed. If checked, uncheck the Everything (no firewall) box, and then check the boxes corresponding to the services you wish to make available to the outside world. If you wish to authorize a service which isn't listed here, click on Advanced to manually enter the port numbers to open.

[Tip] Opening Unusual Services

Clicking the Advanced option opens a field named Other ports where you can enter any port to be opened to the outside world. Examples of port specifications are presented just above the input field: use them as a guide. It's possible to specify port ranges by using the : syntax such as 24300:24350/udp.

This Won't Block You from Accessing the Net. Not checking a service in this list won't stop you from connecting to the Internet. It will only prevent people from the Internet connecting to that service on your machine. If you don't plan on hosting any services on your machine (common case for a desktop machine) just leave all boxes unchecked.

How to Disable the Firewall. On the other hand if you wish to disable the firewall and leave all services accessible from the outside, check Everything (no firewall), but please bear in mind that this is very insecure, and therefore not recommended.

3.2. Activating Interactive Firewall Feature

Figure 7.6. Interactive Firewall Options

Interactive Firewall Options

Stay Informed of Connections on your Machine. The interactive firewall can warn you of connection attempts on your machine by displaying alert popups through the network applet. Check the Use Interactive Firewall option to activate this feature.

Port scan detection

Activate this option to be warned of malicious attempts to access your machine.

Other entries corresponding to open ports

Next you are shown a checkbox for each port you have chosen to open during the previous step. Activating them will popup a warning each time a connection attempt is made on those ports.

3.3. Which Interface to Protect

The next step consists of selecting the network interface connected to the Internet.

Figure 7.7. The Internet Interface

The Internet Interface

If you don't know which interfaces you have connected for the Internet, you can check the system network configuration (see Section 1.3, “Reconfiguring Interfaces”). You can finally click OK to install the required packages, activate the firewall and enjoy your secure Internet connection.