After several years of using ipchains / iptables scripts borrowed from friends and several sites, then tweaking them by hand I finally chickened out into using Guard Dog for all the machines which are directly connected to the net.

It is easy to use but somehow leaves me feeling a bit uneasy no particular reason…

  • You might want to fix the URL.

  • IMHO, minimise use of firewall rules. Make internal services listen only on internal interface as far as possible. For the rest iptables is there anyway.

    • Make internal services listen only on internal interface

      Thats what I am doing…