iptables for retards...
Go to file
ktsaou 513f0518aa Re-wrote 'helpme' to detect multiple IPs and networks per interfaces,
and to produce multiple interfaces for each IP. This means that FireHOL
is somewhat smart to match IPs with networks and interfaces, to detect
networks behind gateways, default gateways on point-to-point interfaces,
and to produce router statements matching the interfaces detected above.
2003-03-05 00:11:56 +00:00
doc Minor changes in 'helpme' and changes in documentation to reflect the 2003-02-26 22:26:16 +00:00
examples *** empty log message *** 2003-01-07 02:03:09 +00:00
.cvs Added to FireHOL distribution. 2002-12-07 00:48:34 +00:00
.spec FireHOL has been changed to be "smart" when REJECTing packets. 2003-01-01 03:12:17 +00:00
buildrpm.sh Updated all example configurations 2002-12-31 15:44:34 +00:00
ChangeLog *** empty log message *** 2003-02-18 20:44:08 +00:00
COPYING Added to FireHOL distribution. 2002-12-07 00:48:34 +00:00
firehol.sh Re-wrote 'helpme' to detect multiple IPs and networks per interfaces, 2003-03-05 00:11:56 +00:00
get-iana.sh CVS test 2002-10-27 12:44:42 +00:00
README *** empty log message *** 2002-12-22 20:46:19 +00:00
TODO *** empty log message *** 2003-01-06 01:49:36 +00:00

$Id: README,v 1.4 2002/12/22 20:46:19 ktsaou Exp $

FireHOL, an iptables stateful packet filtering firewall for humans!
Copyright (C) 2002 Costa Tsaousis <costa@tsaousis.gr>


LICENSE
-------
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 2 of the License, or
(at your option) any later version.

This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
GNU General Public License for more details.

You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA


DOCUMENTATION
-------------
If you received this program in as a RPM, documentation should be
installed at /usr/share/doc/firehol-X.XX.
Otherwise, documentation should be available in the doc/ directory
of the .tar.bz2 archive you received.

In any case, you can also find the documentation online, at:

                     http://firehol.sf.net


INSTALLATION
------------

RPM
~~~
RPM distributions automatically install the program. After a RPM
installation, FireHOL should be available at /etc/init.d/firehol
and its default configuration at /etc/firehol.conf.
Please use the chkconfig system utility to enable/disable
firehol's activity at boot time.

TAR.BZ2
~~~~~~~
This type of distribution includes all the files in the directory
where you uncompress it.
To make FireHOL start at boot time you have to add it to the startup
procedure of your operating system.

Three things are needed to start FireHOL properly:

1. Move firehol.sh to the directory where your startup scripts exist
   and rename it to firehol (i.e. remove the .sh).

2. Make sure FireHOL is called with something like:

         /path/to/startup/scripts/firehol start

3. Make sure there is a valid configuration file in /etc/firehol.conf

This is it.


IMPORTANT NOTES
---------------
If you decide to use FireHOL regularly (or permanently) you have to
understand that it will control your firewall and therefore be a
key point of your security. You should do something to be notified
of bugs or other kind of problems as soon as they appear.

I suggest to subscribe to the notification engine of freshmeat.net
under this project or to monitor FireHOL's file releases at
sourceforge.net. Both of these services will keep you anonymous
(to me) but will update you if and when new releases become available.


CONTRIBUTING
------------
I'll be glad to receive your ideas, patches, case studies, service
definitions, etc.

Here is my e-mail: costa@tsaousis.gr

Please note however that this is my personal e-mail that I read
just once per day and in some cases, once every a few days. If you
want some faster response, you can always use the mailing lists
and forums under this project at sourceforge.

Kind Regard
Costa Tsaousis