<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Shorewall on Dataprd.Com</title>
		<link>https://dataprd.com/tags/shorewall/</link>
		<description>Recent content in Shorewall on Dataprd.Com</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Fri, 14 Mar 2014 13:40:59 +0000</lastBuildDate>
		
			<atom:link href="https://dataprd.com/tags/shorewall/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Setting up a firewall to secure a Hadoop cluster&#39;s network with Shorewall</title>
				<link>https://dataprd.com/posts/setting-up-a-firewall-to-secure-hadoop-clusters-network-with-shorewall/</link>
				<pubDate>Fri, 14 Mar 2014 13:40:59 +0000</pubDate>
				<guid>https://dataprd.com/posts/setting-up-a-firewall-to-secure-hadoop-clusters-network-with-shorewall/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;http://shorewall.net/&#34;&gt;Shorewall&lt;/a&gt; is a tool to configure Linux inbuilt IPTables in an easy and understandable way. Assume we have a basic setup: &lt;em&gt;Lan | Firewall with Proxy server | Internet&lt;/em&gt; &lt;img src=&#34;https://dataprd.com/images/uploads/2014/08/Shorewall_Proxy.png&#34; alt=&#34;Network_Config&#34;&gt; A secure setup is to:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;ACCEPT HTTP(80) and HTTPS(443) from LAN to NET&lt;/li&gt;&#xA;&lt;li&gt;ACCEPT special services ports from specific LAN to NET (like e-banking)&lt;/li&gt;&#xA;&lt;li&gt;ACCEPT only the needed FW services from LAN to FW - SSH(22) and MAIL(25,443,993,&amp;hellip;) to FW (if mail server is on FW)&lt;/li&gt;&#xA;&lt;li&gt;ACCEPT only the needed FW services from NET to FW - SSH(22) with IP restriction (and SSH key) and MAIL(25,443,993,&amp;hellip;) to FW (if mail server is on FW)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;SSH port can be changed&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;LOC to LOC connections are not possible to be governed by FW, therefore all allowed&lt;/li&gt;&#xA;&lt;li&gt;REJECT any incoming connection (other than above) to LAN or FW&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Shorewall configuration - with some additional examples on the syntax and rules:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Secure Linux based environment - communication for SMEs</title>
				<link>https://dataprd.com/posts/secure-environment-for-communication/</link>
				<pubDate>Thu, 13 Mar 2014 13:11:16 +0000</pubDate>
				<guid>https://dataprd.com/posts/secure-environment-for-communication/</guid>
				<description>&lt;p&gt;Data governance procedures include the management of communication assets (e-mail, instant messaging, phone calls), which are considered as business secrets. While small enterprises should make calculations on using the cloud as the price benefit might be worth the negative impact on data management and ownership, a medium/large sized company is suggested to use own solutions with own security and data backup policies. Hereby - &lt;em&gt;in brief&lt;/em&gt; - I present an &lt;em&gt;exemplary cost-effective,&lt;/em&gt; secure setup for small to medium enterprises own infrastructure based on encrypted communication and messaging storage with data security and backup in mind. &lt;em&gt;This is a high-level overview: data governance practices, backup policies, disaster recovery, update procedures, security testing, physical security, etc. are to be defined&lt;/em&gt;. &lt;img src=&#34;https://dataprd.com/images/uploads/2014/08/MidSecure.png&#34; alt=&#34;Middle sized company secure network&#34;&gt; Linux based servers: CentOS or Ubuntu Office 1: ~100-200 users&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
