<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Firewall on Ubuntu</title>
	<atom:link href="http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/feed/" rel="self" type="application/rss+xml" />
	<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/</link>
	<description>I just wish my mouth had a backspace key.</description>
	<lastBuildDate>Sun, 25 Oct 2009 14:11:17 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: dbn</title>
		<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/#comment-210</link>
		<dc:creator>dbn</dc:creator>
		<pubDate>Mon, 08 Jun 2009 19:44:37 +0000</pubDate>
		<guid isPermaLink="false">http://hostintruder.wordpress.com/?p=171#comment-210</guid>
		<description>Good article! For all the h473rZ - 0-day vulnerabilities have, will, and do exist. If a software service has a 0-day vulnerability and a software service is publically accessible on the web because you have not configured iptables, and a bot/worm/scriptkiddie comes a&#039;knocking, your system has no chance of survival...that is, if the intent is destructive or you have something you wanted kept private. Performance is a non-issue unless you want to block entire subnets, and even then unless you are hit really hard by a botnet (DDoS) be thankful the firewall is stopping it instead of complaining about performance. (botnets aren&#039;t typically used to break into home pc&#039;s unless you are in/famous, big business, or a branch of some government.) Configure iptables already!</description>
		<content:encoded><![CDATA[<p>Good article! For all the h473rZ &#8211; 0-day vulnerabilities have, will, and do exist. If a software service has a 0-day vulnerability and a software service is publically accessible on the web because you have not configured iptables, and a bot/worm/scriptkiddie comes a&#8217;knocking, your system has no chance of survival&#8230;that is, if the intent is destructive or you have something you wanted kept private. Performance is a non-issue unless you want to block entire subnets, and even then unless you are hit really hard by a botnet (DDoS) be thankful the firewall is stopping it instead of complaining about performance. (botnets aren&#8217;t typically used to break into home pc&#8217;s unless you are in/famous, big business, or a branch of some government.) Configure iptables already!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fibonacci</title>
		<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/#comment-26</link>
		<dc:creator>Fibonacci</dc:creator>
		<pubDate>Sun, 10 Aug 2008 00:38:10 +0000</pubDate>
		<guid isPermaLink="false">http://hostintruder.wordpress.com/?p=171#comment-26</guid>
		<description>Hi!
Thanks for the article, very interesting. Can you please post more GUI screenshots next time, although the installation process was helpful too.</description>
		<content:encoded><![CDATA[<p>Hi!<br />
Thanks for the article, very interesting. Can you please post more GUI screenshots next time, although the installation process was helpful too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: X</title>
		<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/#comment-25</link>
		<dc:creator>X</dc:creator>
		<pubDate>Sat, 09 Aug 2008 23:25:13 +0000</pubDate>
		<guid isPermaLink="false">http://hostintruder.wordpress.com/?p=171#comment-25</guid>
		<description>Thank you for posting this guide.  You did a good job on it and I like your graphics too.</description>
		<content:encoded><![CDATA[<p>Thank you for posting this guide.  You did a good job on it and I like your graphics too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hostintruder</title>
		<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/#comment-24</link>
		<dc:creator>hostintruder</dc:creator>
		<pubDate>Sat, 09 Aug 2008 22:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://hostintruder.wordpress.com/?p=171#comment-24</guid>
		<description>Maybe this will used some resources(very little) but as far as I know all Linux distros come with a firewall and have since kernel 2.0. Since Linux 2.4, the firewall built into the kernel is iptables.
Unless you give iptables some rules, it allows everything. Tools like Firestarter are not firewalls themselves(as said it above) but utilities to make it easier to configure iptables. In other words, it&#039;s just as Graphical User Interface. 

Another reason to have a firewall is that if later on you decide to install a new service such as SSH or Remote Desktop (VNC), you will probably want to control who can access these services by installing a software firewall.

Since my Ubuntu desktop is my sole machine that connects directly to the Internet, then I think that it&#039;s a good idea to configure one. By the way, thanks for the command &lt;code&gt;sudo netstat -cpnut&lt;/code&gt;, I never heard about it but it&#039;s very useful.</description>
		<content:encoded><![CDATA[<p>Maybe this will used some resources(very little) but as far as I know all Linux distros come with a firewall and have since kernel 2.0. Since Linux 2.4, the firewall built into the kernel is iptables.<br />
Unless you give iptables some rules, it allows everything. Tools like Firestarter are not firewalls themselves(as said it above) but utilities to make it easier to configure iptables. In other words, it&#8217;s just as Graphical User Interface. </p>
<p>Another reason to have a firewall is that if later on you decide to install a new service such as SSH or Remote Desktop (VNC), you will probably want to control who can access these services by installing a software firewall.</p>
<p>Since my Ubuntu desktop is my sole machine that connects directly to the Internet, then I think that it&#8217;s a good idea to configure one. By the way, thanks for the command <code>sudo netstat -cpnut</code>, I never heard about it but it&#8217;s very useful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: X</title>
		<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/#comment-23</link>
		<dc:creator>X</dc:creator>
		<pubDate>Sat, 09 Aug 2008 21:30:02 +0000</pubDate>
		<guid isPermaLink="false">http://hostintruder.wordpress.com/?p=171#comment-23</guid>
		<description>You can monitor your connections and programs as follows without installing a firewall:

sudo netstat -cpnut

If you close down your uneeded open ports, what benefit does the firewall give you?  what does the firewall do to system performance and resources?</description>
		<content:encoded><![CDATA[<p>You can monitor your connections and programs as follows without installing a firewall:</p>
<p>sudo netstat -cpnut</p>
<p>If you close down your uneeded open ports, what benefit does the firewall give you?  what does the firewall do to system performance and resources?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hostintruder</title>
		<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/#comment-22</link>
		<dc:creator>hostintruder</dc:creator>
		<pubDate>Sat, 09 Aug 2008 18:01:07 +0000</pubDate>
		<guid isPermaLink="false">http://hostintruder.wordpress.com/?p=171#comment-22</guid>
		<description>Maybe you are right, but with a firewall, you can monitor which program is accessing the internet. You have a better control on your machine.</description>
		<content:encoded><![CDATA[<p>Maybe you are right, but with a firewall, you can monitor which program is accessing the internet. You have a better control on your machine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: luckydev</title>
		<link>http://hostintruder.wordpress.com/2008/08/09/firewall-on-ubuntu/#comment-21</link>
		<dc:creator>luckydev</dc:creator>
		<pubDate>Sat, 09 Aug 2008 17:38:53 +0000</pubDate>
		<guid isPermaLink="false">http://hostintruder.wordpress.com/?p=171#comment-21</guid>
		<description>If you are a desktop user, I personally feel you dont need a firewall...all u need to do is to install the security updates sent by ubuntu. firewall is very necessay in cases of servers.</description>
		<content:encoded><![CDATA[<p>If you are a desktop user, I personally feel you dont need a firewall&#8230;all u need to do is to install the security updates sent by ubuntu. firewall is very necessay in cases of servers.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
