#shorewall — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #shorewall, aggregated by home.social.
-
I started a company!
“What? Huh? Why?”
Those are some of the many questions I was asking myself. Simply… Looking to challenge the brain in different ways than what I’m normally doing.
How it began – In my personal time while trying to secure my own personal hosted infrastructure, I was noticing that there wasn’t an efficient or effective way to block bad threat actors (nasty hackers) on the Internet.
The typical (tedious) approach has always been:
- I see a bad connection from IP1, therefore I must block IP1.
- I see a bad connection from IP2, therefore I must block IP2.
- I see a bad connection from IP3, therefore I must block IP3.
- ….
- Repeat until you lose all sense of sanity.
The problem with this approach is that you end up getting stuck in a game of whack-a-mole. Who do you think wins? Trick question – it’s not you!
I put a different idea together – what if bad threat actors run their hacking world like a business and focus on cost optimization and automation. Novel idea right?
How does this apply to what I do? Well if I were to run a business like theirs, I would figure out how to “copy/paste” my attacks in creative ways. To do this, I would choose a (cheap) hosting provider that has resources that I can use for my desired purposes. Once the hosting provider is identified, I’m going to figure out ways to spin up new resources in a quick manner in a different location (i.e. automation).
New Resource + New Location = New IP Address To Attack From
Now that I know this, let the hacking begin!
Do you see how the game of whack-a-mole starts?
What does my company do?
I have a few products available now, but the one product that solves the above problem is a product called Molasses Masses.
How does it work?
Rather than blocking on a per-IP basis, I get all the subnets for that hosting provider that the hacker is using and then block those. The idea is that remote connections coming to my/your hosted services, should not come from other hosting providers. It should be from people like you reading this article!
Now it’s possible that you or your business partners get caught up in the block list – no problem! You can exclude your own and/or business partner subnets from the specifically curated list of subnets that you download.
How effective it this?
I’ve seen a reduction of attacks of up to 90%* from all my honeypots on the Internet.
Why would you use this?
Got remote users that need to VPN into your organization?
Got hosted services that should be accessed from actual users, and not random bots sitting in hosted environments?
Then this is the product for you!
Integrations available?
Very simply, It’s a flat text file of curated subnets that you can use in your own policies..
These are the supported platforms available today to consume my product:
- Linux (shorewall)
- Cisco – Firepower Threat Defense (FTD)
- Fortinet – Fortigate Firewalls
- Palo Alto Networks – PAN-OS and Prisma Access.
Curious to test it out? 7-day free trials available.
Use discount code MM2026 to snag a 20% discount on checkout for the first 50 customers 🙂
* As with all things in life – your mileage may vary. You might have a different environment compared to mine which gives different results. #AntiHacking #BotMitigation #BruteForceProtection #CiscoFTD #CloudSecurity #CyberSecurity #Cybersecurity #DDoSProtection #Fortigate #Honeypot #InfoSec #IPBlocking #MolassesMasses #NetworkSecurity #PaloAltoNetworks #security #Shorewall #SubnetFiltering #SysAdmin #technology #threatIntelligence #VPNTrust #ZeroTrust -
Krass, der Hauptentwickler/ Maintainer Thomas M. Eastep des #Shorewall Firewall Tools ist mittlerweile ca. 81 Jahre alt, seinen letzten commit 2024 hat er also mit ca. 79 Jahren gemacht.
(hochgerechnet aus https://sourceforge.net/p/shorewall/mailman/message/35458915/ )
-
Krass, der Hauptentwickler/ Maintainer Thomas M. Eastep des #Shorewall Firewall Tools ist mittlerweile ca. 81 Jahre alt, seinen letzten commit 2024 hat er also mit ca. 79 Jahren gemacht.
(hochgerechnet aus https://sourceforge.net/p/shorewall/mailman/message/35458915/ )
-
Krass, der Hauptentwickler/ Maintainer Thomas M. Eastep des #Shorewall Firewall Tools ist mittlerweile ca. 81 Jahre alt, seinen letzten commit 2024 hat er also mit ca. 79 Jahren gemacht.
(hochgerechnet aus https://sourceforge.net/p/shorewall/mailman/message/35458915/ )
-
Krass, der Hauptentwickler/ Maintainer Thomas M. Eastep des #Shorewall Firewall Tools ist mittlerweile ca. 81 Jahre alt, seinen letzten commit 2024 hat er also mit ca. 79 Jahren gemacht.
(hochgerechnet aus https://sourceforge.net/p/shorewall/mailman/message/35458915/ )
-
Krass, der Hauptentwickler/ Maintainer Thomas M. Eastep des #Shorewall Firewall Tools ist mittlerweile ca. 81 Jahre alt, seinen letzten commit 2024 hat er also mit ca. 79 Jahren gemacht.
(hochgerechnet aus https://sourceforge.net/p/shorewall/mailman/message/35458915/ )
-
Has anyone ever built their own router? I was thinking: DSL modem (ALLnet) -> Raspberry Pi with RMN520N HAT.
#router #diyrouter #openwrt #linux #archlinux #shorewall #modem #RaspberryPi
-
Has anyone ever built their own router? I was thinking: DSL modem (ALLnet) -> Raspberry Pi with RMN520N HAT.
#router #diyrouter #openwrt #linux #archlinux #shorewall #modem #RaspberryPi
-
Has anyone ever built their own router? I was thinking: DSL modem (ALLnet) -> Raspberry Pi with RMN520N HAT.
#router #diyrouter #openwrt #linux #archlinux #shorewall #modem #RaspberryPi
-
Has anyone ever built their own router? I was thinking: DSL modem (ALLnet) -> Raspberry Pi with RMN520N HAT.
#router #diyrouter #openwrt #linux #archlinux #shorewall #modem #RaspberryPi
-
On the weekend, I switched on a #foomuuri #nftables firewall.
I have been using #shorewall for so long that it is in my fingers.
Foomuuri is likeable and capable. I am finding my way around her peculiarities. Definitely stepping forward into it rather than falling back on my comfortable habits.
-
On the weekend, I switched on a #foomuuri #nftables firewall.
I have been using #shorewall for so long that it is in my fingers.
Foomuuri is likeable and capable. I am finding my way around her peculiarities. Definitely stepping forward into it rather than falling back on my comfortable habits.
-
On the weekend, I switched on a #foomuuri #nftables firewall.
I have been using #shorewall for so long that it is in my fingers.
Foomuuri is likeable and capable. I am finding my way around her peculiarities. Definitely stepping forward into it rather than falling back on my comfortable habits.
-
On the weekend, I switched on a #foomuuri #nftables firewall.
I have been using #shorewall for so long that it is in my fingers.
Foomuuri is likeable and capable. I am finding my way around her peculiarities. Definitely stepping forward into it rather than falling back on my comfortable habits.
-
Перевел свои :calculate: сервера с #shorewall на #nftables. Насколько же все стало проще и логичней!
-
Перевел свои :calculate: сервера с #shorewall на #nftables. Насколько же все стало проще и логичней!
-
Перевел свои :calculate: сервера с #shorewall на #nftables. Насколько же все стало проще и логичней!
-
Перевел свои :calculate: сервера с #shorewall на #nftables. Насколько же все стало проще и логичней!
-
If you've followed our recent posts, you already know that we gave Shorewall a try to tidy up our VPN firewall rules and gain full overview about our configuration. Our migration to Shorewall has been successful and we'd like to share some insights in our configuration:
"Keeping the Wireguard VPN firewall clear with Shorewall" - https://blog.zero-iee.com/en/posts/vpn-firewall-shorewall/
Shorewall by Tom Eastep is just perfect for small to mid size firewall deployments that are mostly static and not too complex. One of our developers uses OpnSense and PfSense for more complex scenarios in his private projects.
Which firewall / configuration tool do you use and why?
#shorewall #firewall #wireguard #vpn #teamzero #zeroiee #blog #techblog #linux #debian
-
If you've followed our recent posts, you already know that we gave Shorewall a try to tidy up our VPN firewall rules and gain full overview about our configuration. Our migration to Shorewall has been successful and we'd like to share some insights in our configuration:
"Keeping the Wireguard VPN firewall clear with Shorewall" - https://blog.zero-iee.com/en/posts/vpn-firewall-shorewall/
Shorewall by Tom Eastep is just perfect for small to mid size firewall deployments that are mostly static and not too complex. One of our developers uses OpnSense and PfSense for more complex scenarios in his private projects.
Which firewall / configuration tool do you use and why?
#shorewall #firewall #wireguard #vpn #teamzero #zeroiee #blog #techblog #linux #debian
-
If you've followed our recent posts, you already know that we gave Shorewall a try to tidy up our VPN firewall rules and gain full overview about our configuration. Our migration to Shorewall has been successful and we'd like to share some insights in our configuration:
"Keeping the Wireguard VPN firewall clear with Shorewall" - https://blog.zero-iee.com/en/posts/vpn-firewall-shorewall/
Shorewall by Tom Eastep is just perfect for small to mid size firewall deployments that are mostly static and not too complex. One of our developers uses OpnSense and PfSense for more complex scenarios in his private projects.
Which firewall / configuration tool do you use and why?
#shorewall #firewall #wireguard #vpn #teamzero #zeroiee #blog #techblog #linux #debian
-
If you've followed our recent posts, you already know that we gave Shorewall a try to tidy up our VPN firewall rules and gain full overview about our configuration. Our migration to Shorewall has been successful and we'd like to share some insights in our configuration:
"Keeping the Wireguard VPN firewall clear with Shorewall" - https://blog.zero-iee.com/en/posts/vpn-firewall-shorewall/
Shorewall by Tom Eastep is just perfect for small to mid size firewall deployments that are mostly static and not too complex. One of our developers uses OpnSense and PfSense for more complex scenarios in his private projects.
Which firewall / configuration tool do you use and why?
#shorewall #firewall #wireguard #vpn #teamzero #zeroiee #blog #techblog #linux #debian
-
If you've followed our recent posts, you already know that we gave Shorewall a try to tidy up our VPN firewall rules and gain full overview about our configuration. Our migration to Shorewall has been successful and we'd like to share some insights in our configuration:
"Keeping the Wireguard VPN firewall clear with Shorewall" - https://blog.zero-iee.com/en/posts/vpn-firewall-shorewall/
Shorewall by Tom Eastep is just perfect for small to mid size firewall deployments that are mostly static and not too complex. One of our developers uses OpnSense and PfSense for more complex scenarios in his private projects.
Which firewall / configuration tool do you use and why?
#shorewall #firewall #wireguard #vpn #teamzero #zeroiee #blog #techblog #linux #debian
-
We're currently evaluating Shorewall [1] as a Firewall / iptables configuration tool.
Configuring iptables manually [2] works, but can get messy and thus is error prone. For our VPN server with its many customer VPNs, we are looking for a clearer solution that can be easily configured via configuration files. One of our developers has already used Shorewall and is impressed by the software. It was therefore a natural decision to take a look at it.
Initial experiments have gone well!
[1]: https://shorewall.org/
[2]: https://blog.zero-iee.com/posts/multi-tenant-wireguard-vpn-server/ -
We're currently evaluating Shorewall [1] as a Firewall / iptables configuration tool.
Configuring iptables manually [2] works, but can get messy and thus is error prone. For our VPN server with its many customer VPNs, we are looking for a clearer solution that can be easily configured via configuration files. One of our developers has already used Shorewall and is impressed by the software. It was therefore a natural decision to take a look at it.
Initial experiments have gone well!
[1]: https://shorewall.org/
[2]: https://blog.zero-iee.com/posts/multi-tenant-wireguard-vpn-server/ -
We're currently evaluating Shorewall [1] as a Firewall / iptables configuration tool.
Configuring iptables manually [2] works, but can get messy and thus is error prone. For our VPN server with its many customer VPNs, we are looking for a clearer solution that can be easily configured via configuration files. One of our developers has already used Shorewall and is impressed by the software. It was therefore a natural decision to take a look at it.
Initial experiments have gone well!
[1]: https://shorewall.org/
[2]: https://blog.zero-iee.com/posts/multi-tenant-wireguard-vpn-server/ -
We're currently evaluating Shorewall [1] as a Firewall / iptables configuration tool.
Configuring iptables manually [2] works, but can get messy and thus is error prone. For our VPN server with its many customer VPNs, we are looking for a clearer solution that can be easily configured via configuration files. One of our developers has already used Shorewall and is impressed by the software. It was therefore a natural decision to take a look at it.
Initial experiments have gone well!
[1]: https://shorewall.org/
[2]: https://blog.zero-iee.com/posts/multi-tenant-wireguard-vpn-server/ -
We're currently evaluating Shorewall [1] as a Firewall / iptables configuration tool.
Configuring iptables manually [2] works, but can get messy and thus is error prone. For our VPN server with its many customer VPNs, we are looking for a clearer solution that can be easily configured via configuration files. One of our developers has already used Shorewall and is impressed by the software. It was therefore a natural decision to take a look at it.
Initial experiments have gone well!
[1]: https://shorewall.org/
[2]: https://blog.zero-iee.com/posts/multi-tenant-wireguard-vpn-server/ -
Gestern hatte ich auf einem Test Server einmal firewalld ausprobiert. Gefallen hat mir das Zonenmodell, das netfilter mitbringt. Die Syntax ist verhältnismäßig schnell und einfach zu erlernen. Allerdings muss ich gestehen, dass ich ein Fan von Shorewall bin und somit war es ein kleiner aber informativer Abstecher.
Was verwendet Ihr, um die Firewall eurer Server zu konfigurieren?
#server #linux #admin #firewall #firewalld #shorewall #iptables #netfilter #ufw #administration #redhat #debian #arch #suse #itsicheheit
-
@greppy I prefer keeping the pi-hole off the perimeter if I can help it, personally.
I've done the #Debian thing before (and moved to #Shorewall from iptables at some point. These days, I'm using a #Synology RT2600ac as mine, having upgraded from an #openwrt flashed router.
-
@greppy I prefer keeping the pi-hole off the perimeter if I can help it, personally.
I've done the #Debian thing before (and moved to #Shorewall from iptables at some point. These days, I'm using a #Synology RT2600ac as mine, having upgraded from an #openwrt flashed router.
-
@greppy I prefer keeping the pi-hole off the perimeter if I can help it, personally.
I've done the #Debian thing before (and moved to #Shorewall from iptables at some point. These days, I'm using a #Synology RT2600ac as mine, having upgraded from an #openwrt flashed router.
-
@greppy I prefer keeping the pi-hole off the perimeter if I can help it, personally.
I've done the #Debian thing before (and moved to #Shorewall from iptables at some point. These days, I'm using a #Synology RT2600ac as mine, having upgraded from an #openwrt flashed router.
-
What #firewall frontend do you use on your #linux distro?
Please boost, for more range 📶
#iptables #nftables #ipset #firewalld #shorewall #ufw #gnulinux #network #networksecurity #distro
-
What #firewall frontend do you use on your #linux distro?
Please boost, for more range 📶
#iptables #nftables #ipset #firewalld #shorewall #ufw #gnulinux #network #networksecurity #distro
-
What #firewall frontend do you use on your #linux distro?
Please boost, for more range 📶
#iptables #nftables #ipset #firewalld #shorewall #ufw #gnulinux #network #networksecurity #distro
-
What #firewall frontend do you use on your #linux distro?
Please boost, for more range 📶
#iptables #nftables #ipset #firewalld #shorewall #ufw #gnulinux #network #networksecurity #distro
-
What #firewall frontend do you use on your #linux distro?
Please boost, for more range 📶
#iptables #nftables #ipset #firewalld #shorewall #ufw #gnulinux #network #networksecurity #distro
-
-
-
-
Setting up Wireguard VPN with IPv6
#Debian #firewall #IPv6 #Linux #security #Shorewall #vpn #Wireguard
https://blog.frehi.be/2022/06/11/setting-up-wireguard-vpn-with-ipv6/