hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Web Hosting Talk Tutorials : Hosting Security and Technology Tutorials : APF FireWall Installation [Easy]
Reply

Forum Jump

APF FireWall Installation [Easy]

Reply Post New Thread In Hosting Security and Technology Tutorials Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old
WebHostingTalk Lover
 
Join Date: Mar 2003
Location: New York City
Posts: 7,391
Lightbulb

APF FireWall Installation [Easy]


Hi,

This is a pretty simple How-to for installing APF Firewall.

1) Install:
wget http://www.rfxnetworks.com/downloads/apf-current.rpm
rpm -Uvh apf-current.rpm

2) Edit:
/etc/apf/conf.apf

DEVM="0" - set to 0 only if you are sure that firewall works good

(Common Cpanel Ports, please re-configure for your use)
TCP_CPORTS=" 21,22,25,53,80,110,143,443,465,993,995,2082,2083,2086,2087,2095,2096,3306,7786" (in one line!)

UDP_CPORTS="37,53,873"

Many other options in which you can enable inside the config. Please take time to configure.

3) Restart APF


To Enable Pings:

pico -w /etc/apf/icmp.rules
Uncomment:

# Uncomment to enable pings
# $IPT -t filter -A INPUT -p icmp --icmp-type 8 -m limit --limit $ICMP_LIM/s -j ACCEPT
Then restart APF

------------------------------
commands:
/etc/rc.d/init.d/apf stop
/etc/rc.d/init.d/apf start
/etc/rc.d/init.d/apf restart

Thanks to EV1 Forum for much info on this.


Last edited by eBoundary; 01-19-2004 at 10:18 AM.


Sponsored Links
  #2  
Old
Web Hosting Master
 
Join Date: Jan 2001
Location: Illinois, USA
Posts: 7,147
Thanks for the How-To!

Hopefully someone can follow this up with a detailed tutorial on how to configure APF

<edit>signature removed</edit>


Last edited by choon; 02-17-2004 at 03:29 PM.
  #3  
Old
Web Hosting Master
 
Join Date: Apr 2001
Posts: 2,588
3 things,

1. I believe Ryan ( APF Author ) has recommended against the rpm.. and it may be outdated.

2. Why reboot?

3. This how-to seems to be fairly outdated, compared to the most recent APF versions.

Edit: I should also note for future readers that the above seems to be targeted towards cpanel / whm systems.

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:16 PM.
Sponsored Links
  #4  
Old
WebHostingTalk Lover
 
Join Date: Mar 2003
Location: New York City
Posts: 7,391
Quote:
Originally posted by Haze
3 things,

1. I believe Ryan ( APF Author ) has recommended against the rpm.. and it may be outdated.

2. Why reboot?

3. This how-to seems to be fairly outdated, compared to the most recent APF versions.

Edit: I should also note for future readers that the above seems to be targeted towards cpanel / whm systems.
Sorry, I meant by restart apf, not reboot..
It be great if you can contribute a How-To for APF. (No RPM)
Also, these arent targeted towards only cpanel systems.

Cheers.

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:16 PM.
  #5  
Old
Web Hosting Master
 
Join Date: May 2003
Posts: 1,639
The documentation for APF is very clear and it is a very simple install. Basically untar it and run ./install.sh. The version outlined above is an old one as the port defining sections have changed in 0.9.3. In Ryan's forums there are sections of what he leaves open for different panels.

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:17 PM.
  #6  
Old
WebHostingTalk Lover
 
Join Date: Mar 2003
Location: New York City
Posts: 7,391
Hi,

Ok anyways, here's installing without using RPM, this is a newer version of APF.


wget http://www.rfxnetworks.com/downloads/apf-current.tar.gz

tar -xzf apf-current.tar.gz

cd /apf-0.9.3_3
./install.sh

Your set
Remember to edit config etc..and read the README.

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:17 PM.
  #7  
Old
Junior Guru
 
Join Date: Apr 2002
Location: Canada
Posts: 246
http://www.webhostgear.com/61.html

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:18 PM.
  #8  
Old
WebHostingTalk Lover
 
Join Date: Mar 2003
Location: New York City
Posts: 7,391
Quote:
Originally posted by rfxn
http://www.webhostgear.com/61.html
Yea just saw that one posted on burst's forum, pretty good how-to as well

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:18 PM.
  #9  
Old
Web Hosting Master
 
Join Date: Dec 2003
Location: Canada
Posts: 791
lsmod: QM_MODULES: Function not implemented

Unable to load iptables module (ip_tables), aborting.

Any ideas?

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:18 PM.
  #10  
Old
Web Hosting Master
 
Join Date: Dec 2003
Location: Canada
Posts: 791
Nevermind, I got it running.

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:19 PM.
  #11  
Old
Web Hosting Guru
 
Join Date: Apr 2003
Posts: 267
and how to remove APF ? I'v install a rpm (old one ) and how to remove it to install a new one ?

  #12  
Old
WebHostingTalk Lover
 
Join Date: Mar 2003
Location: New York City
Posts: 7,391
Try rpm -e apf

<edit>signature removed</edit>


Last edited by choon; 02-09-2004 at 09:19 PM.
  #13  
Old
Junior Guru
 
Join Date: Jun 2002
Posts: 233
Quote:
Originally posted by 93.3
lsmod: QM_MODULES: Function not implemented

Unable to load iptables module (ip_tables), aborting.

Any ideas?

<edit>signature removed</edit>
If your kernel is compiled with iptables statically instead of as a module you need to do this in the conf.apf MONOKERN="0" Set it to "1" and then try start APF again.

  #14  
Old
WebHostingTalk Lover
 
Join Date: Mar 2003
Location: New York City
Posts: 7,391
Quote:
Originally posted by SynHost
If your kernel is compiled with iptables statically instead of as a module you need to do this in the conf.apf MONOKERN="0" Set it to "1" and then try start APF again.
Yep, that should take care of it. Older version though don't have this option.

  #15  
Old
Junior Guru
 
Join Date: Feb 2004
Posts: 206
lsmod: QM_MODULES: Function not implemented

I am only getting the following error: lsmod: QM_MODULES: Function not implemented wil making the same change to the config file work as well?

Thanks, Kevin

Reply

Related posts from TheWhir.com
Title Type Date Posted
MaxCDN and CloudProxy Partner to Make Website Delivery Fast and Secure Web Hosting News 2014-05-01 08:33:47
Rackspace Offers Brocade Vyatta vRouter in Limited Availability Web Hosting News 2013-05-31 10:17:42
GoGrid Adds New Firewall Services to Cloud SDN Architecture Web Hosting News 2013-04-11 10:50:21
WHD.global 2013: SiteLock Adds Web Application Firewall and CDN to Security Portfolio Web Hosting News 2013-03-19 13:48:01
Phoenix NAP Adds Firewall and Storage Capabilities to Secured Servers Web Hosting News 2013-01-21 14:15:08


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
WHT Host Brief Email:

We respect your privacy. We will never sell, rent, or give away your address to any outside party, ever.

Advertisement:
Web Hosting News:
WHT Membership
WHT Membership



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?