Go Back   HostGator Peer Support Forums > HostGator Peer Support Forums > Linux VPS Support

Notices

Reply
 
Thread Tools
  #1  
Old 12-26-2010, 09:13 AM
Garry's Avatar
Garry Garry is offline
Hatchling Croc
 
Join Date: Jul 2008
Location: UK
Posts: 25
Question What Firewall for VPS

Hi,

What do you recommend for a firewall for my new VPS.
In the pass I have used CSF (Config Security Firewall).

What do you use?
__________________
Regards,
Garry
Reply With Quote
  #2  
Old 12-26-2010, 01:21 PM
chaloupe chaloupe is offline
King Croc
 
Join Date: Nov 2004
Location: Dieppe, New-Brunswick, Canada
Posts: 1,427
Default Re: What Firewall for VPS

Garry,

I still use CSF on my side and would also advise you to use it.

The only downside is CSF is a software on the server and not a hardware before your server. Hardware are too expensive any way.
__________________
Jean Boudreau - IT for local businesses
It's all about automation!
Any data backup of your company?

Reply With Quote
  #3  
Old 12-26-2010, 01:26 PM
Garry's Avatar
Garry Garry is offline
Hatchling Croc
 
Join Date: Jul 2008
Location: UK
Posts: 25
Default Re: What Firewall for VPS

Thanks for the reply.
I have installed CSF and enabled it etc...
__________________
Regards,
Garry
Reply With Quote
  #4  
Old 12-26-2010, 02:51 PM
chaloupe chaloupe is offline
King Croc
 
Join Date: Nov 2004
Location: Dieppe, New-Brunswick, Canada
Posts: 1,427
Default Re: What Firewall for VPS

Garry,

Excellent choice!

If you have any issues with the CSF firewall, they are great threads on this forums. We will be glad to help you if you face any problems.

Regards,
__________________
Jean Boudreau - IT for local businesses
It's all about automation!
Any data backup of your company?

Reply With Quote
  #5  
Old 03-10-2012, 08:46 AM
chaloupe chaloupe is offline
King Croc
 
Join Date: Nov 2004
Location: Dieppe, New-Brunswick, Canada
Posts: 1,427
Default Re: What Firewall for VPS

CSF firewall are easier to manage or to change settings on the fly. Everything can be done in WHM control panel.

They also give you a lot of information to tweak your VPS for more robust protection (check server security button).

The CSF firewall does not only open or close port. It has many features which is far more than just a straight out of the box hardware or software firewall.

I've been using it since at least 2005 on many servers.
__________________
Jean Boudreau - IT for local businesses
It's all about automation!
Any data backup of your company?

Reply With Quote
  #6  
Old 03-10-2012, 08:53 AM
chaloupe chaloupe is offline
King Croc
 
Join Date: Nov 2004
Location: Dieppe, New-Brunswick, Canada
Posts: 1,427
Default Re: What Firewall for VPS

Here's a the list of what CSF will help you with:


Server Check
Check /tmp permissions
Check /tmp ownership
Check /tmp is mounted as a filesystem
Check /tmp is mounted noexec,nosuid
Check /etc/cron.daily/logrotate for /tmp noexec workaround
Check /var/tmp permissions
Check /var/tmp ownership
Check /var/tmp is mounted as a filesystem
Check /var/tmp is mounted noexec,nosuid
Check /usr/tmp permissions
Check /usr/tmp ownership
Check /usr/tmp is mounted as a filesystem or is a symlink to /tmp
Check /dev/shm is mounted noexec,nosuid
Check for DNS recursion restrictions
Check for DNS random query source port
Check server runlevel
Check nobody cron
Check Operating System support
Check perl version
Check MySQL version
Check MySQL LOAD DATA disallows LOCAL
Check SUPERUSER accounts
Check for cxs
Check for IPv6
Check for kernel logger


SSH/Telnet Check
Check SSHv1 is disabled
Check SSH on non-standard port
Check SSH UseDNS
Check telnet port 23 is not in use
Check shell limits
Check Background Process Killer


Mail Check
Check root forwarder
Check exim for extended logging (log_selector)
Check exim weak SSL/TLS Ciphers (tls_require_ciphers)
Check for maildir conversion
Check dovecot weak SSL/TLS Ciphers (ssl_cipher_list)


Apache Check
Check apache version
Check suPHP
Check Suexec
Check apache for mod_security
Check apache for FrontPage
Check Apache weak SSL/TLS Ciphers (SSLCipherSuite)
Check apache for TraceEnable
Check apache for ServerSignature
Check apache for ServerTokens
Check apache for FileETag
Check mod_userdir protection


PHP Check
Check php version (/usr/local/bin/php)
Check php for enable_dl or disabled dl()
Check php for disable_functions
Check php for ini_set disabled
Check php for register_globals
Check php for Suhosin
Check php open_basedir protection


WHM Settings Check
Check cPanel login is SSL only
Check boxtrapper is disabled
Check max emails per hour is set
Check whether users can reset passwords via email
Check whether native cPanel SSL is enabled
Check compilers
Check Anonymous FTP Logins
Check Anonymous FTP Uploads
Check pure-ftpd weak SSL/TLS Ciphers (TLSCipherSuite)
Check FTP Logins with Root Password
Check allow remote domains
Check block common domains
Check allow park domains
Check proxy subdomains
Check proxy subdomains for new users
Check cPAddons update email to owner
Check cPAddons update email to root
Check cPanel tree
Check cPanel updates
Check package updates
Check security updates
Check melange chat server
Check Accounts that can access a cPanel user account
Check cPanel php for register_globals
Check cPanel php.ini file for register_globals
Check cPanel passwords in email
Check core dumps
Check Cookie IP Validation
Check MD5 passwords with Apache
Check Referrer Blank Security
Check Referrer Security
Check HTTP Authentication
Check Security Tokens
Check Parent Security
Check Domain Lookup Security
Check SMTP Tweak
Check nameservers WARNING


Server Services Check
Check server startup for cups
Check server startup for xfs
Check server startup for atd
Check server startup for nfslock
Check server startup for canna
Check server startup for FreeWnn
Check server startup for cups-config-daemon
Check server startup for iiim
Check server startup for mDNSResponder
Check server startup for nifd
Check server startup for rpcidmapd
Check server startup for bluetooth
Check server startup for anacron
Check server startup for gpm
Check server startup for saslauthd
Check server startup for avahi-daemon
Check server startup for avahi-dnsconfd
Check server startup for hidd
Check server startup for pcscd
Check server startup for sbadm
__________________
Jean Boudreau - IT for local businesses
It's all about automation!
Any data backup of your company?

Reply With Quote
  #7  
Old 03-10-2012, 09:56 PM
wesslayneb's Avatar
wesslayneb wesslayneb is offline
Junior Croc
 
Join Date: Dec 2010
Location: Kentucky USA
Posts: 176
Default Re: What Firewall for VPS

Using CFS now along with IPTables, working great.
__________________
HostGator makes being a Web Host extremely easy and simple.
Reply With Quote
  #8  
Old 03-15-2012, 04:14 PM
bcaa8ra bcaa8ra is offline
Junior Croc
 
Join Date: Aug 2008
Location: Sarasota, FL
Posts: 106
Default Re: What Firewall for VPS

chaloupe mentioned csf does not close ports. So do we leave HG firewall running and add csf?
Also, I am a VPS newbie do I put a ticket in to have csf installed?

Thanks...
__________________
Bernie Clark
MAKO Web Sales LLC
Sarasota Florida’s Only Certified Paypal Developer!

Sarasota: 941-870-2271
Toll Free: 877-625-6932
http://www.makoweb.com
Reply With Quote
  #9  
Old 03-15-2012, 04:45 PM
quietFinn's Avatar
quietFinn quietFinn is offline
Veteran Croc
 
Join Date: Feb 2005
Posts: 3,557
Default Re: What Firewall for VPS

Quote:
Originally Posted by bcaa8ra View Post
chaloupe mentioned csf does not close ports. So do we leave HG firewall running and add csf?
Also, I am a VPS newbie do I put a ticket in to have csf installed?

Thanks...
You misundestood what he said.
CSF closes all ports, and in it's configuration you specify what ports to open.
__________________
quietFinn - netFinn Finland
"Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss
Reply With Quote
  #10  
Old 03-25-2012, 10:34 PM
skyrim77 skyrim77 is offline
Baby Croc
 
Join Date: Feb 2011
Posts: 70
Default Re: What Firewall for VPS

Another vote for CSF.
__________________
Elder Scroll Skyrim Fansite http://elderscrollsskyrim.com/
Reply With Quote
  #11  
Old 05-17-2012, 02:11 PM
sorathia sorathia is offline
Hatchling Croc
 
Join Date: Jun 2010
Posts: 22
Default Re: What Firewall for VPS

Could someone please point me in the right direction on how to install / configure CSF? If I open a ticket, can hostgator install CSF for me?

Thanks!
Reply With Quote
  #12  
Old 05-17-2012, 02:16 PM
quietFinn's Avatar
quietFinn quietFinn is offline
Veteran Croc
 
Join Date: Feb 2005
Posts: 3,557
Default Re: What Firewall for VPS

Quote:
Originally Posted by sorathia View Post
Could someone please point me in the right direction on how to install / configure CSF? If I open a ticket, can hostgator install CSF for me?

Thanks!
http://www.configserver.com/free/csf/install.txt
__________________
quietFinn - netFinn Finland
"Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall nightmare www.toao.net Linux VPS Support 4 05-19-2010 04:56 PM
It's not my firewall....what else? melovemoney Shared Hosting Support 6 04-02-2007 12:36 PM

All times are GMT -5. The time now is 01:31 PM.