Network Blog

Network Blog – Tech Blog

Last update in Monday, February 6th 2012
Stay update with this site articles
  • Home
  • About
  • Advertising
  • Archieve
  • Contact
  • Sitemap

How to install KISS Firewall ( Linux )

Posted by admin in Friday, August 29th 2008   
Topics: Firewall
Tags: Kiss+Firewall
1 Comment

How to install KISS Firewall

Brief Summary

KISS My Firewall is a FREE iptables script designed for a typical web server. It takes advantage of the latest firewall technologies including stateful packet inspection and connection tracking. It also contains some preventative measures for port scanning, DoS attacks, and IP spoofing, among other things.

KISS My Firewall 2 is very easy to install and does not require any initial configuration. It will work with any stock installation of Ensim WEBppliance Basic & Pro, Plesk, and Webmin. Cpanel installations require some modifications.

What’s New in Version 2?

The biggest change is that it does not require any initial configuration. With version 2, you won’t automatically lock yourself out of your server unless you set some of the variables incorrectly. It also does extensive error checking and is distributed as a tar file. This solves a lot of the issues that were present with the older version. In addition, version 2 is highly configurable and was tested to work with the latest version of iptables – version 1.2.8.

 kiss-firewall

HOW TO: Install KISS My Firewall

1) When logged in as root ( “su -” ), type:

2) cd /usr/bin

3) Download KISS firewall
wget http://www.geocities.com/steve93138/kiss-2.0.1.tar.gz

4) Extract it
tar zxvf kiss-2.0.1.tar.gz

If you want to block an offenders IP address/subnet, simply edit the BLOCK_LIST variable in the /usr/bin/kiss file. You can separate IP addresses and subnet’s with a space. Once you are finished, restart the firewall.

5) Editing the config
pico -w /usr/bin/kiss

You must change config from: NOTE see our Printer friendly version to avoid text wrapping!

# Uncomment to allow DNS zone transfers
#
#$IPTABLES -A INPUT -i eth0 -p udp –sport 53 –dport 53 -m state –state NEW -j ACCEPT
#$IPTABLES -A INPUT -i eth0 -p tcp –sport 53 –dport 53 -m state –state NEW -j ACCEPT
#$IPTABLES -A OUTPUT -o eth0 -p udp –sport 53 –dport 53 -m state –state NEW -j ACCEPT
#$IPTABLES -A OUTPUT -o eth0 -p tcp –sport 53 –dport 53 -m state –state NEW -j ACCEPT

To:

# Uncomment to allow DNS zone transfers
#
$IPTABLES -A INPUT -i eth0 -p udp –sport 53 –dport 53 -m state –state NEW -j ACCEPT
$IPTABLES -A INPUT -i eth0 -p tcp –sport 53 –dport 53 -m state –state NEW -j ACCEPT
$IPTABLES -A OUTPUT -o eth0 -p udp –sport 53 –dport 53 -m state –state NEW -j ACCEPT
$IPTABLES -A OUTPUT -o eth0 -p tcp –sport 53 –dport 53 -m state –state NEW -j ACCEPT

6) Cpanel Users Config – other users ignore this step
In the /usr/bin/kiss file scroll down until you see the line: TCP_IN and replace it with this.

TCP_IN=”20 21 25 53 80 110 143 443 995 2082:2083 2086:2087 2095:2096 3306″

Now find the line that says TCP_OUT and replace it with this.

TCP_OUT=”21 22 25 37 43 53 80 443 873 2089″

7) Save the changes and restart the firewall
Ctrl + X then Y

Restart KISS by typing:
kiss restart

That’s it! You now have a nice IPtables firewall running that’s easy to configure and use.

Firewall Commands
That’s it! To get it running anywhere on the command line, you simply type:
kiss start

To stop the firewall, type:
kiss stop

To get status information, type:
kiss status

Restart KISS by typing:
kiss restart

Popularity: 10% [?]

Related Post

  • APF Deny ALL for SSH – Limit IP Connections
  • Firewall
  • APF (Advanced Policy Firewall) For Linux

Spread the word

Digg this post

Bookmark to delicious

Stumble the post

Add to your technorati favourite

Subscribes to this post

1 users responded to this post

Sam said in September 2nd, 2008 at 1:25 am    

What would you recommend kiss orApf and why ?

Thanks.

Sam.

Leave Your Comments Below

« There are many positives with VoIP
Zimbra to offer Ubuntu Linux support »
  • Categories

    • Adverts
    • Anti-Virus
    • Apple
    • Blogging
    • Browser
    • Computer
    • Email
    • Firefox
    • Firewall
    • Gadgets
    • Hacking
    • Internet
    • iPhone
    • iPod
    • Linux
    • Mac
    • Microsoft
    • Notebook
    • Open Source
    • Security
    • Softwares
    • Sony
    • Storage
    • Technology
    • Uncategorized
    • VoIP
  • Blogroll

    • Asia SEO
    • Fashion Blog
    • Web Hosting
  • Pages

    • About
    • Advertising
    • Archieve
    • Contact
    • Sitemap
  • Follow Me On Twitter

    Follow Me on Twitter

Recent Articles

  • Partition Recovery
  • Google caffeine Update !
  • Singapore Domain Registration Tips
  • Free Blogger Templates Designer Themes
  • Music to Your Ears: The New Sony Ericsson Zylo
  • Remanufactured HP C1816A Premium Ink Cartridge
  • What you need to know about Facebook security
  • Best Web Host A Silent Partner
  • Online phone cards
  • Google Pagerank Update (30/Dec/2009 ) !

Most Popular

  • What is S/PDIF?
  • Valuing Network Certifications : Cisco ( CCNA/CCNP ) - Microsoft Certified ( MCSE / MCSA )
  • APF (Advanced Policy Firewall) For Linux
  • There are many positives with VoIP
  • Online phone cards
  • Link Load Balancing
  • Samsung Finesse SCH-R810 Mobile Phone
  • Cisco CCNA / CCNP / BCMSN Exam Review
  • Define Radius Server
  • Best Web Host A Silent Partner

Popular Tags

  • 4004+Chip Advertising+online Anti+Virus APF_Firewall Apple Blogging CCNA Cisco+Exam+Tutorial Computer Dual+Core+Qua+Core ERP+Software Fiber+Cables Firefox Firewall Gadgets Google+chrome Google+Lively Hacking Hyper-V+Windows+Server Internet Internet+Security iPhone iPod IT+Risk+Management Kiss+Firewall Life+Book+P8010 Linux Linux+Desktop Mac MacBook+Pro Microsoft Mobile+Blogging Notebook Open+Source Reciprocal+links SAS+70 Sony Sony+Laptop+TZ SQL+Server+2008 Storage Storage+Software+Memory The+AMUG+Mac+Pro URL+shorteners VoIP Zimbra+Ubuntu+Linux

Recent Feedbacks

  • grigzrh: When you have to renew it, you will go thru hell. My cousin have been trying to renew since dec 2009 and...
  • Larry: I bought my Samsung Finesse through Straight Talk which is far better than MetroPCS because Straight Talk runs...
  • samramirez: I have been using Dish Network for months now and I am satisfied with their service so far. Im glad I...
  • Takashi: What a lovely article ! Thank you. Takashi.
  • Sam: What would you recommend kiss orApf and why ? Thanks. Sam.

Most Commented

  • APF (Advanced Policy Firewall) For Linux  (1)
  • How to install KISS Firewall ( Linux ) (1)
  • Google Launches Virtual World Called 'Lively'  (1)
  • Dish Network – The Way To See The World (1)
  • Samsung Finesse SCH-R810 Mobile Phone (1)
  • Magic Jack Review (1)

Live Traffic

Subscribes

  • stumble
  • technorati add aol netvibes rojo myyahoo modern freedictionary subrss chicklet plusmo newsburst ngsub wwgthis subscribes
©2007-2012 Network Blog
Sponser By Web Hosting Blog Copy Protected

feeds

Valid XHTML   |   Valid CSS