Designing and Implementing Linux Firewalls and QoS.pdf

(8890 KB) Pobierz
Designing and Implementing
Linux Firewalls and QoS using
netfilter, iproute2, NAT, and
L7-filter
Learn how to secure your system and implement QoS
using real-world scenarios for networks of all sizes
Lucian Gheorghe
BIRMINGHAM - MUMBAI
Designing and Implementing Linux Firewalls and QoS
using netfilter, iproute2, NAT, and L7-filter
Copyright © 2006 Packt Publishing
All rights reserved. No part of this book may be reproduced, stored in a retrieval
system, or transmitted in any form or by any means, without the prior written
permission of the publisher, except in the case of brief quotations embedded in
critical articles or reviews.
Every effort has been made in the preparation of this book to ensure the accuracy of
the information presented. However, the information contained in this book is sold
without warranty, either express or implied. Neither the author, Packt Publishing,
nor its dealers or distributors will be held liable for any damages caused or alleged to
be caused directly or indirectly by this book.
Packt Publishing has endeavored to provide trademark information about all the
companies and products mentioned in this book by the appropriate use of capitals.
However, Packt Publishing cannot guarantee the accuracy of this information.
First published: October 2006
Production Reference: 2181006
Published by Packt Publishing Ltd.
32 Lincoln Road
Olton
Birmingham, B27 6PA, UK.
ISBN 1-904811-65-5
www.packtpub.com
Cover Image by
www.visionwt.com
Credits
Author
Lucian Gheorghe
Reviewer
Barrie Dempster
Development Editor
Louay Fatoohi
Assistant Development Editor
Nikhil Bangera
Technical Editor
Niranjan Jahagirdar
Code Testing
Ankur Shah
Editorial Manager
Dipali Chittar
Indexer
Mithil Kulkarni
Proofreader
Chris Smith
Layouts and Illustrations
Shantanu Zagade
Cover Designer
Shantanu Zagade
About the Author
Lucian Gheorghe
has just joined the Global NOC of Interoute, Europe's largest
voice and data network provider. Before Interoute, he was working as a senior
network engineer for Globtel Internet, a significant Internet and Telephony Services
Provider to the Romanian market. He has been working with Linux for more than
8 years putting a strong accent on security for protecting vital data from hackers
and ensuring good quality services for internet customers. Moving to VoIP services
he had to focus even more on security as sensitive billing data is most often stored
on servers with public IP addresses. He has been studying QoS implementations
on Linux to build different types of services for IP customers and also to deliver
good quality for them and for VoIP over the public Internet. Lucian has also been
programming with Perl, PHP, and Smarty for over 5 years mostly developing
in-house management interfaces for IP and VoIP services.
I would like to thank everyone who is reading this book and
the people that run netfilter, iproute2, and L7-filter projects.
Your feedback is very important to me, so drop me a line at
lucian.firewallbook@gmail.com
. The book is far from being
perfect so please send me errata information on the same email
address (I would love to receive erratas from readers because it
will convince me that people who read this book actually
learned something :-))
I want to dedicate this book to my father, my mother, and my
sister—I love you very very much. Many thanks go to the team at
Globtel who were like second family to me, to my girlfriend for
understanding me and standing by me, to Louay and the rest of the
team at Packt Publishing for doing a great job, to Nigel Coulson,
Petr Klobasa and the rest of the people at Interoute for supporting
me, to Claudiu Filip who is one of the most intelligent people I
know, and last, but not least, to the greatest technical author
alive—Cristian Darie.
Zgłoś jeśli naruszono regulamin