Install APF (Advanced Policy Firewall)



Learn Web Hosting Help and Information on mps-web-hosting.com. Install APF (Advanced Policy Firewall) article will help answer your questions on Web Hosting Help and Information.We at mps-web-hosting.com specialize in Web Hosting Help and Information. Web Hosting Help and Information at mps-web-hosting.com provides the most up to date news and articles. If you have questions please do not hesitate to contact us.

APF Site Description of the software: APF is a policy based iptables firewall system designed for ease of use and configuration. It employs a subset of features to satisfy the veteran Linux user and the novice alike. Packaged in tar.gz format and RPM formats, make APF ideal for deployment in many server environments based on Linux.

Summary of features: - global ports configurtion via simple config file - configurable policies for each ip on the system [global config overrides] - powerfull postrouting rules for FWMARK and TOS - plug-in friendly for QoS [CBQ/HTB] - antidos subsystem to stop attacks before they become a significant threat - dshield.org block list support to ban networks exhibiting suspicious activity - advanced set of sysctl parameters for TCP stack hardening - advanced set of filter rules to remove undesired traffic - easy to use firewall managment script - trust based rule files (allow/deny); with advanced syntax support

1. Login to your server via SSH as root.

2. Make /usr/src the current working directory. Type: cd /usr/src

3. Obtain the most curent verison of APF. Type: wget http://rfxnetworks.com/downloads/apf-current.tar.gz

4. Expand the APF tar.gz file. Type: tar -xvzf apf-current.tar.gz

5. Remove the tar.gz file. Type: rm -f apf-current.tar.gz

6. Locate the APF directory. Type: ls -la Look for a directory named apf-#.#/ where #.# represents the version of APF being installed (APF version 0.8.7 would be in a directory apf-0.8.7/ and version 0.9 would be in a directory named apf-0.9).

7. Make the APF directory the current working directory. Use the directory name you located in step 5. Note that the numbers will change as new versions are released. Type: cd apf-0.9

8. Run the APF install. Type: sh ./install.sh

9. Make /etc/apf the current working directory. Type: cd /etc/apf

10. Edit the conf.apf file as desired. Type: pico -w conf.apf

In order for this firewall to work properly you have to edit/add/delete ports. These ports will allow services such as mail, ftp, and ssh to come in and out of the server. If you have changed any ports, please modify them below and add/remove as needed.

# Common ingress (inbound) TCP ports IG_TCP_CPORTS='20,21,22,25,53,80,110,143,443,465, 993,995,2082,2083,2086,2087,2095,2096,3306, 10000,35000_35999' Please note that ports 2082 to port 2095 is mostly used by cpanel, and port 19638 is only use in ensim.

# Common ingress (inbound) UDP ports IG_UDP_CPORTS='20,21,53,1040'

10. After you have finished editing the ports save the file and test APF. CTRL-X, Y to save enter to confirm

11. Start APF. Type: ./apf --start or Type: service apf start

12. If APF is functioning properly and you are not locked out edit the conf.apf again Type: pico -w conf.apf

13. Set the DEVM parameter to 0 DEVM='0'

14. Once done Exit and save the file. CTRL-X, Y to save enter to confirm

15. Restart APF Type: service apf restart

Enabling connections for server monitoring. Some service providers that offer monitoring need access to your server, and access without setting off alarms, firewalls etc. is a good thing. Just becareful which IP(s) you put in here.

1. To allow connections from xx.xx.xx.xx/24 Type: pico -w /etc/apf/allow_hosts.rules

2. At the very end of the file add this line xx.xx.xx.xx/24 Of course replace the xx.xx.xx.xx with the IP address provided to you.

Original: http://www.ukwebmasterforums.com/t4910-install-apf-advanced-policy-firewall.html

Web Hosting UK (http://www.session9.co.uk/ )

Webmaster Forums ( http://www.ukwebmasterforums.com/ )

Web Hosting Affiliate ( http://www.session9.co.uk/web-hosting-affiliate/ )

Domain Reseller ( http://www.domainvendor.co.uk/ )




Bird Flu - Help Protecting Your Family. - New eBook provides help for the developing pandemic. No installation and you turn the pages like a book on your monitor.
Secrets Of A Professional Installer. - Car stereo installation guide from a pro! Over 150 pgs!

Just in time for May, The Cheap Web Hosting Report has a new look based on an open source template by Andreas Viklund. The CWHR staff thinks this is a major improvement and would like to thank Andreas for making this template available to the world.

As part of this site revamp, the article library from the Frugal Webmaster Blog has finally been incorporated directly into the Cheap Web Hosting Report web site. There is no longer a jarring design switch when you read articles. The Frugal Webmaster Blog url will soon be pointing to The Cheap Web Hosting Report web site, at least in the short term. We plan to add new articles to the Library...



Article Index: | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31


More Articles:


1. Dedicated Web Hosting : The Executive Summary
What is Dedicated Web Hosting? Dedicated web hosting can alleviate the need to share hardware or software with any other sites or web pages. Webmasters are given the autonomy to decide on applications that are installed on the server to create specific configurations for their web needs, and have the ability to provide a secure environment for their site. As compared to a shared-server environment, dedicated web hosting offers a peace of mind that a site will be delivered in a reliable and secur…

2. Do You Go With A Dedicated Server Or Not? By Leon Chaddock
For many businesses, finding solutions in dedicated server options is difficult. This is mainly the case because individuals do not know what they are looking at or looking for. What is a dedicated server and do you need one? If you are not sure, then you may want to keep reading! It can make a large difference in your website’s performance.The dedicated server is a web hosting solution that is advanced in that it allows you to own the complete server. It is not shared yet it belongs to y…

3. MS SQL / MySQL - A Case Study
Contact: John Malco Tel: 1-888-898-9699 Cell: 206-799-9696 MS SQL SERVER 2005 POWERS DATA DRIVEN SITES Case Study of Two Web Hosting Companies The release of Microsoft SQL Server 2005 on November 7th 2005 created a buzz around the office for IT professionals. The use of SQL server by businesses as in an in house data server has become increasingly more popular, this same popularity is now beginning to shift to the web hosting industry. With the release of MS SQL 2005 Microsoft had this…

4. Web Hosting: 4 Factors in Choosing a Hosting Company By Richard Martin
When choosing a web hosting company there are a whole lot of different factors that should go into your decision making process. One of the biggest factors should be:1) Phone support. Email support is nice, but email occasionally falls in between the virtual cracks. Getting someone on the phone when your site goes down can take a lot of mystery out of the entire process. A lot of the bigger web hosting companies offer toll free support and weekend hours to boot. Phone support is a great benef…