<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Vuurmuur on Inliniac</title>
    <link>https://inliniac.net/blog/category/vuurmuur/</link>
    <description>Recent content in Vuurmuur on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sun, 24 Feb 2019 19:22:51 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/category/vuurmuur/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vuurmuur 0.8 has been released</title>
      <link>https://inliniac.net/blog/2019/02/24/vuurmuur-0-8-has-been-released/</link>
      <pubDate>Sun, 24 Feb 2019 19:22:51 +0000</pubDate>
      <guid>https://inliniac.net/blog/2019/02/24/vuurmuur-0-8-has-been-released/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve just pushed the 0.8 release. See my announcement &lt;a href=&#34;https://sourceforge.net/p/vuurmuur/mailman/message/36591637/&#34;&gt;here&lt;/a&gt;. Get it from &lt;a href=&#34;https://github.com/inliniac/vuurmuur/releases/tag/0.8&#34;&gt;github&lt;/a&gt; or the &lt;a href=&#34;ftp://ftp.vuurmuur.org/releases/0.8/&#34;&gt;ftp&lt;/a&gt; &lt;a href=&#34;ftp://ftp.vuurmuur.org/releases/0.8/&#34;&gt;server&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Largest changes:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;ipv6 support using ip6tables&lt;/li&gt;&#xA;&lt;li&gt;logging uses nflog - initial work by Fred Leeflang&lt;/li&gt;&#xA;&lt;li&gt;connection logging and viewer&lt;/li&gt;&#xA;&lt;li&gt;add rpfilter and improved helper support&lt;/li&gt;&#xA;&lt;li&gt;a &amp;lsquo;dialog&amp;rsquo; based setup wizard&lt;/li&gt;&#xA;&lt;li&gt;single code base / package&lt;/li&gt;&#xA;&lt;li&gt;massive code cleanup&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;I plan to continue to work on Vuurmuur, but it will likely remain at a low pace. Suricata development is simply taking too much of my time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur Development Update</title>
      <link>https://inliniac.net/blog/2017/01/12/vuurmuur-development-update/</link>
      <pubDate>Thu, 12 Jan 2017 15:40:51 +0000</pubDate>
      <guid>https://inliniac.net/blog/2017/01/12/vuurmuur-development-update/</guid>
      <description>&lt;p&gt;Over the holidays I&amp;rsquo;ve spent some time refreshing the Vuurmuur code. One major thing that is now done is that the 3 different &amp;lsquo;projects&amp;rsquo; (libvuurmuur, vuurmuur and vuurmuur-conf) are now merged into a single &amp;lsquo;project&amp;rsquo;. This means that a single &amp;lsquo;./configure &amp;amp;&amp;amp; make &amp;amp;&amp;amp; make install&amp;rsquo; now installs everything.&lt;/p&gt;&#xA;&lt;p&gt;When I originally started Vuurmuur I had much bigger dreams for it than eventually materialized. Also, I didn&amp;rsquo;t understand autotools very well, so it was easier to keep the project split up. At some point there were even 5 projects!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur 0.8rc1 released</title>
      <link>https://inliniac.net/blog/2013/01/25/vuurmuur-0-8rc1-released/</link>
      <pubDate>Fri, 25 Jan 2013 16:45:34 +0000</pubDate>
      <guid>https://inliniac.net/blog/2013/01/25/vuurmuur-0-8rc1-released/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/08/vuurmuur-connview-small.png&#34; alt=&#34;&#34;&gt;I just released a new &lt;a href=&#34;http://www.vuurmuur.org&#34;&gt;Vuurmuur&lt;/a&gt; version: 0.8rc1. The first release candidate for the 0.8 series. This release improves IPv6 support a lot. The wizard is now also fully functional. Try &amp;ldquo;vuurmuur_conf &amp;ndash;wizard&amp;rdquo;.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Improved IPv6 support: #115&lt;/li&gt;&#xA;&lt;li&gt;Improved Debian packages, switching to nflog as default for logging.&lt;/li&gt;&#xA;&lt;li&gt;Fix connection viewer not showing accounting on newer systems. #141&lt;/li&gt;&#xA;&lt;li&gt;Amd64 packages for Debian and Ubuntu are now available through the apt server. #83&lt;/li&gt;&#xA;&lt;li&gt;Switch from &amp;ldquo;state&amp;rdquo; match to &amp;ldquo;conntrack&amp;rdquo; match for connection tracking.&lt;/li&gt;&#xA;&lt;li&gt;Services now support possible protocols. #63&lt;/li&gt;&#xA;&lt;li&gt;Add support for rpfilter match. #137&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Get this release from the ftp server:&#xA;&lt;a href=&#34;ftp://ftp.vuurmuur.org/releases/0.8rc1/Vuurmuur-0.8rc1.tar.gz&#34;&gt;ftp://ftp.vuurmuur.org/releases/0.8rc1/Vuurmuur-0.8rc1.tar.gz&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Setting up an IPS with Fedora 17, Suricata and Vuurmuur</title>
      <link>https://inliniac.net/blog/2012/10/13/setting-up-an-ips-with-fedora-17-suricata-and-vuurmuur/</link>
      <pubDate>Sat, 13 Oct 2012 11:07:19 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/10/13/setting-up-an-ips-with-fedora-17-suricata-and-vuurmuur/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/08/vuurmuur-connview-small.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;I recently found out that Fedora includes Vuurmuur in it&amp;rsquo;s repositories. Since Suricata is also included, I figured I would do a quick write up on how to setup a Fedora IPS. While writing it turned more into a real &amp;ldquo;howto&amp;rdquo;, so I decided to submit it to Howtoforge.&lt;/p&gt;&#xA;&lt;p&gt;It can be found &lt;a href=&#34;http://www.howtoforge.com/how-to-set-up-an-ips-intrusion-prevention-system-on-fedora-17&#34;&gt;here one HowtoForge&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/suricata2.png&#34; alt=&#34;&#34;&gt;Vuurmuur on Fedora is at the 0.7 version, which is still the current stable. It&amp;rsquo;s rather old though, and it reminds me again I need to make sure the 0.8 branch gets to a stable release soon. The Suricata included in Fedora 17 is 1.2.1, with &lt;a href=&#34;http://suricata-ids.org/2012/10/03/suricata-1-3-2-available/&#34;&gt;1.3.2&lt;/a&gt; expected to land any day now.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur 0.8beta4 released</title>
      <link>https://inliniac.net/blog/2012/08/31/vuurmuur-0-8beta4-released/</link>
      <pubDate>Fri, 31 Aug 2012 13:20:08 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/08/31/vuurmuur-0-8beta4-released/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/08/vuurmuur-connview-small.png&#34;&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/08/vuurmuur-connview-small.png&#34; alt=&#34;&#34;&gt;&lt;/a&gt; I just released a new &lt;a href=&#34;http://www.vuurmuur.org&#34; title=&#34;Vuurmuur Firewall&#34;&gt;Vuurmuur&lt;/a&gt; version. The last release was in 2009, so it has been a while.&lt;/p&gt;&#xA;&lt;p&gt;This release adds basic IPv6 support. The state of the IPv6 support is incomplete, but quite functional.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Supported features are:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;- rules generation&#xA;- log viewing&#xA;- setting IPv6 addresses in hosts, networks and interfaces&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Unsupported features are:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;- connection viewer&#xA;- NAT&#xA;- blocklist&#xA;- IPv6 address to Vuurmuur name conversion in the log&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur IPv6</title>
      <link>https://inliniac.net/blog/2011/03/31/vuurmuur-ipv6/</link>
      <pubDate>Thu, 31 Mar 2011 21:14:43 +0000</pubDate>
      <guid>https://inliniac.net/blog/2011/03/31/vuurmuur-ipv6/</guid>
      <description>&lt;p&gt;The last few years Vuurmuur development has been very slow, not to say pretty much stagnant. This had a couple of reasons. The first is that my attention was drawn to other projects, mostly Suricata these days. The second reason is that Vuurmuur pretty much does all I want. The third reason is that despite some minor contributions, no other developer has stepped up to take over.&lt;/p&gt;&#xA;&lt;p&gt;Meanwhile, people continued using Vuurmuur, it made it&amp;rsquo;s way into Debian, got removed from it again, made it&amp;rsquo;s way into Ubuntu. Lately, every few weeks someone would ask me if Vuurmuur was still being developed. My answer always was &amp;ldquo;yes, but very slowly&amp;rdquo;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ohloh</title>
      <link>https://inliniac.net/blog/2010/06/30/ohloh/</link>
      <pubDate>Wed, 30 Jun 2010 08:47:54 +0000</pubDate>
      <guid>https://inliniac.net/blog/2010/06/30/ohloh/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.ohloh.net/&#34;&gt;Ohloh&lt;/a&gt; is a pretty cool site for keeping track of projects and programmers. It&amp;rsquo;s an easy way to keep track of the development in a project and gives a nice indication of how actively it&amp;rsquo;s being developed. It has some social networkish features too, such as individual developers giving each other &amp;ldquo;kudos&amp;rdquo;.&lt;/p&gt;&#xA;&lt;p&gt;The code analysis is pretty nice: it gives statistics on code base size, growth, comment ratio, languages used, etc. Per developer it tracks quite a few stats as well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur rpms</title>
      <link>https://inliniac.net/blog/2009/11/03/vuurmuur-rpms/</link>
      <pubDate>Tue, 03 Nov 2009 15:44:49 +0000</pubDate>
      <guid>https://inliniac.net/blog/2009/11/03/vuurmuur-rpms/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://projectdaenney.org/&#34;&gt;Daniele Sluijters&lt;/a&gt; has spend quite an effort at creating Vuurmuur rpms for Fedora 11 and CentOS 5, both 32 bit and 64 bit. The packages are available at the Vuurmuur ftp-server here: &lt;a href=&#34;ftp://ftp.vuurmuur.org/releases/0.7/contrib/&#34;&gt;ftp://ftp.vuurmuur.org/releases/0.7/contrib/&lt;/a&gt; Currently we have packages for 0.7, hopefully 0.8beta2 will follow later. Thanks Daniele!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur development</title>
      <link>https://inliniac.net/blog/2009/11/01/vuurmuur-development/</link>
      <pubDate>Sun, 01 Nov 2009 17:46:07 +0000</pubDate>
      <guid>https://inliniac.net/blog/2009/11/01/vuurmuur-development/</guid>
      <description>&lt;p&gt;Ever since I&amp;rsquo;ve been working on the OISF engine I&amp;rsquo;ve been unable to spend much time on my Vuurmuur project. Luckily it seems development is picking up some speed again because there are some (new) people working on some improvements. Two development branches have been started in svn. The first is &amp;ldquo;nflog&amp;rdquo; which is meant for the development of support for libnetfilter_log to replace the current syslog based vuurmuur_log.&lt;/p&gt;&#xA;&lt;p&gt;The second is called &amp;ldquo;ipv6&amp;rdquo; and is meant for adding IPv6 support to Vuurmuur as a frontend to ip6tables. This is going to be quite an effort, but I&amp;rsquo;m excited that it got started!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur 0.7 is out</title>
      <link>https://inliniac.net/blog/2009/04/04/vuurmuur-07-is-out/</link>
      <pubDate>Sat, 04 Apr 2009 08:04:25 +0000</pubDate>
      <guid>https://inliniac.net/blog/2009/04/04/vuurmuur-07-is-out/</guid>
      <description>&lt;p&gt;A new version of Vuurmuur is out: 0.7. This release mainly fixes bugs and build issues. Translations are generated and installed again, lots of traffic shaping fixes were made.&lt;/p&gt;&#xA;&lt;p&gt;Support for pmtu MSS clamping was added, as was support for NAT source port randomization.&lt;/p&gt;&#xA;&lt;p&gt;See &lt;a href=&#34;http://www.vuurmuur.org/trac/wiki/Changelog&#34;&gt;http://www.vuurmuur.org/trac/wiki/Changelog&lt;/a&gt; for all changes.&lt;/p&gt;&#xA;&lt;p&gt;Debs for Debian and Ubuntu are available, see&#xA;&lt;a href=&#34;http://www.vuurmuur.org/trac/wiki/InstallationDebian&#34;&gt;http://www.vuurmuur.org/trac/wiki/InstallationDebian&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The source installer and Autopackage are on the ftp server:&#xA;&lt;a href=&#34;ftp://ftp.vuurmuur.org/releases/0.7/&#34;&gt;ftp://ftp.vuurmuur.org/releases/0.7/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Looking forward, I&amp;rsquo;m planning on improving the services handling in 0.8. Especially supporting all protocols from /etc/protocols, instead of just a small list of hardcodes ones. Check &lt;a href=&#34;http://www.vuurmuur.org/trac/milestone/0.8&#34;&gt;http://www.vuurmuur.org/trac/milestone/0.8&lt;/a&gt; to monitor the plans and progress on the 0.8 release. Suggestions &amp;amp; help are welcome!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur 0.7 getting close</title>
      <link>https://inliniac.net/blog/2009/03/31/vuurmuur-07-getting-close/</link>
      <pubDate>Tue, 31 Mar 2009 15:42:35 +0000</pubDate>
      <guid>https://inliniac.net/blog/2009/03/31/vuurmuur-07-getting-close/</guid>
      <description>&lt;p&gt;The next stable version of &lt;a href=&#34;http://www.vuurmuur.org&#34;&gt;Vuurmuur&lt;/a&gt;, &lt;a href=&#34;http://www.vuurmuur.org/trac/milestone/0.7&#34;&gt;0.7&lt;/a&gt;, is getting close. Last week I released release candidate 3. If you&amp;rsquo;re a Vuurmuur user, please try 0.7rc3 and report back to me on how it works! For a list of changes, please see &lt;a href=&#34;http://www.vuurmuur.org/trac/query?status=closed&amp;amp;milestone=0.7&#34;&gt;the closed tickets&lt;/a&gt;. Thanks!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Checking out SourceForge&#39;s Marketplace</title>
      <link>https://inliniac.net/blog/2009/01/06/checking-out-sourceforges-marketplace/</link>
      <pubDate>Tue, 06 Jan 2009 14:26:31 +0000</pubDate>
      <guid>https://inliniac.net/blog/2009/01/06/checking-out-sourceforges-marketplace/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve registered myself as a seller of services on SourceForge&amp;rsquo;s Open Source &lt;a href=&#34;http://sourceforge.net/services/buy/index.php&#34;&gt;Marketplace&lt;/a&gt;. I&amp;rsquo;ve done so offering software development services for the &lt;a href=&#34;http://www.snort.org/&#34;&gt;Snort&lt;/a&gt;, &lt;a href=&#34;http://snort-inline.sf.net/&#34;&gt;Snort_inline&lt;/a&gt; and &lt;a href=&#34;http://www.vuurmuur.org&#34;&gt;Vuurmuur&lt;/a&gt; projects. I was wondering if anyone has any experience (good or bad) with the Marketplace system, either as a buyer or seller of services. Let me know!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur makes it into Debian (Sid)</title>
      <link>https://inliniac.net/blog/2008/12/09/vuurmuur-makes-it-into-debian-sid/</link>
      <pubDate>Tue, 09 Dec 2008 14:08:57 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/12/09/vuurmuur-makes-it-into-debian-sid/</guid>
      <description>&lt;p&gt;Thanks to the hard work of Debian&amp;rsquo;s Daniel Baumann Vuurmuur has been included in Debian unstable/Sid. This hopefully means that Vuurmuur will be getting a lot more users. Eventually it should get into testing and even stable, although the next release &amp;ldquo;lenny&amp;rdquo; will come too soon for that. The &amp;ldquo;lenny&amp;rdquo; feature freeze was already in place before Vuurmuur got included in Sid. Anyway, for me this is big news!&lt;/p&gt;&#xA;&lt;p&gt;See here for the packages:&#xA;&lt;a href=&#34;http://packages.debian.org/sid/libvuurmuur0&#34;&gt;http://packages.debian.org/sid/libvuurmuur0&lt;/a&gt; &lt;a href=&#34;http://packages.debian.org/sid/vuurmuur&#34;&gt;http://packages.debian.org/sid/vuurmuur&lt;/a&gt; &lt;a href=&#34;http://packages.debian.org/sid/vuurmuur-conf&#34;&gt;http://packages.debian.org/sid/vuurmuur-conf&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Vuurmuur version numbering scheme</title>
      <link>https://inliniac.net/blog/2008/09/22/new-vuurmuur-version-numbering-scheme/</link>
      <pubDate>Mon, 22 Sep 2008 15:15:12 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/09/22/new-vuurmuur-version-numbering-scheme/</guid>
      <description>&lt;p&gt;Today I&amp;rsquo;ve changed the versioning scheme for &lt;a href=&#34;http://www.vuurmuur.org&#34;&gt;Vuurmuur&lt;/a&gt;. I was unhappy with the scheme for quite some time already. Versions like 0.5.73 are not making much sense in my view. Originally, my intention was to have a scheme like the linux kernel at the time had. Even versions for stable releases, odd versions for unstable/development releases. The idea was that the 0.5.x development series would some day become a 0.6 stable, after which the 0.7 development series would begin. Of course, that never happened. Instead, I added the alpha releases that became the real development releases and the 0.5.x effectively became the stable releases. So we ended up with releases like 0.5.74 alpha 6. In my opinion quite confusing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Support for source port randomization in Vuurmuur</title>
      <link>https://inliniac.net/blog/2008/07/25/support-for-source-port-randomization-in-vuurmuur/</link>
      <pubDate>Fri, 25 Jul 2008 21:50:59 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/07/25/support-for-source-port-randomization-in-vuurmuur/</guid>
      <description>&lt;p&gt;One of the workarounds for the current DNS problems is that servers introduce source port randomization.  So it&amp;rsquo;s time for you to patch your DNS server so it uses random source ports. If for some reason you are unable to do that, iptables can help. Michael Rash has a good write up of how that works &lt;a href=&#34;http://cipherdyne.org/blog/2008/07/mitigating-dns-cache-poisoning-attacks-with-iptables.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In Vuurmuur there is now a per rule option, that can be enabled for the SNAT, MASQ, PORTFW, DNAT and BOUNCE actions, called &amp;lsquo;random&amp;rsquo;. This passes the &amp;lsquo;&amp;ndash;random&amp;rsquo; option to the iptables rules Vuurmuur creates. Note that you need a recent distro for this. Debian Etch is too old, Ubuntu Hardy is fine. The new functionality is just released in Vuurmuur 0.5.74 alpha 6. Check it out!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Snort_inline processes with Vuurmuur</title>
      <link>https://inliniac.net/blog/2007/11/12/multiple-snort_inline-processes-with-vuurmuur/</link>
      <pubDate>Mon, 12 Nov 2007 21:29:58 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/11/12/multiple-snort_inline-processes-with-vuurmuur/</guid>
      <description>&lt;p&gt;One of the cool things of the &lt;a href=&#34;http://snort-inline.sf.net/&#34;&gt;Snort_inline&lt;/a&gt; project is the support for NFQUEUE. NFQUEUE is the new queuing mechanism to push packets from the kernel to userspace so a userspace program can issue a verdict on it. What makes NFQUEUE cooler than it&amp;rsquo;s predecessor ip_queue is that it supports multiple queue&amp;rsquo;s. This means that there can be more than one Snort_inline process inspecting and judging traffic. The challenge is to make sure that each Snort_inline instance sees all traffic belonging to a certain connection so Snort_inline can do stateful inspection on it. Luckily, &lt;a href=&#34;http://www.vuurmuur.org/&#34;&gt;Vuurmuur&lt;/a&gt; makes it very easy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GUI part of Vuurmuur traffic shaping done</title>
      <link>https://inliniac.net/blog/2007/11/02/gui-part-of-vuurmuur-traffic-shaping-done/</link>
      <pubDate>Thu, 01 Nov 2007 23:03:18 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/11/02/gui-part-of-vuurmuur-traffic-shaping-done/</guid>
      <description>&lt;p&gt;The GUI part of Vuurmuur&amp;rsquo;s traffic shaping is done. That means it&amp;rsquo;s in a usable state. It&amp;rsquo;s probably rough around the edges, but anyone is invited to give it a try. Below two screens.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2007/11/vuurmuur-shape-rule.png&#34; title=&#34;Vuurmuur shape rule settings.&#34;&gt;Vuurmuur shape rule settings.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2007/11/vuurmuur-shape-rule.png&#34; title=&#34;Vuurmuur shape rule settings.&#34;&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2007/11/vuurmuur-shape-rule.png&#34; alt=&#34;Vuurmuur shape rule settings.&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The per rule shaping settings.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2007/11/vuurmuur-shape-iface.png&#34; title=&#34;Vuurmuur shape interface settings.&#34;&gt;Vuurmuur shape interface settings.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2007/11/vuurmuur-shape-iface.png&#34; title=&#34;Vuurmuur shape interface settings.&#34;&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2007/11/vuurmuur-shape-iface.png&#34; alt=&#34;Vuurmuur shape interface settings.&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The per interface settings for the shaping.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur gets traffic shaping</title>
      <link>https://inliniac.net/blog/2007/10/02/vuurmuur-gets-traffic-shaping/</link>
      <pubDate>Tue, 02 Oct 2007 19:11:12 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/10/02/vuurmuur-gets-traffic-shaping/</guid>
      <description>&lt;p&gt;The last weeks I&amp;rsquo;ve been working on adding traffic shaping support to Vuurmuur. The work is largely done, only the GUI part is still missing. But using vuurmuur_script it is already usable in the current SVN trunk. I&amp;rsquo;ve written before about my shaping ideas &lt;a href=&#34;http://www.inliniac.net/blog/2006/08/16/vuurmuur-first-baby-steps-in-traffic-shaping.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The support currently focuses on three different options:&lt;/p&gt;&#xA;&lt;p&gt;1. Limiting bandwidth usage by rules.&lt;/p&gt;&#xA;&lt;p&gt;Per rule a limit can be set for the maximum amount of bandwidth all traffic from this rule uses. Both directions of a connection have different limits. The in_max and out_max options can be added to existing rules for this. The syntax of the in_max and out_max is simple: out_max=15kbps means that traffic in the source to destination direction of a rule can at max use 15 kb/s.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Interview about Vuurmuur on security.nl</title>
      <link>https://inliniac.net/blog/2007/10/02/interview-about-vuurmuur-on-securitynl/</link>
      <pubDate>Tue, 02 Oct 2007 11:10:44 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/10/02/interview-about-vuurmuur-on-securitynl/</guid>
      <description>&lt;p&gt;The Dutch security site &lt;a href=&#34;http://www.security.nl&#34;&gt;security.nl&lt;/a&gt; has interviewed me about the &lt;a href=&#34;http://www.vuurmuur.org/&#34;&gt;Vuurmuur&lt;/a&gt; project. The (Dutch language) article can be found &lt;a href=&#34;http://www.security.nl/article/17064/1/Hollandse_Vuurmuur_weerstaat_commerci%EBle_beveiliging_%28Interview%29.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Thanks to Joran Polak of security.nl for giving me the opportunity to tell something about this project!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur developments</title>
      <link>https://inliniac.net/blog/2007/09/17/vuurmuur-developments-2/</link>
      <pubDate>Mon, 17 Sep 2007 15:34:49 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/09/17/vuurmuur-developments-2/</guid>
      <description>&lt;p&gt;Last weeks I&amp;rsquo;ve spend many hours on my &lt;a href=&#34;http://www.vuurmuur.org/&#34;&gt;Vuurmuur Firewall project&lt;/a&gt;. First I&amp;rsquo;ve been improving the code to prepare for a new release. I&amp;rsquo;ve added NFQUEUE support to Vuurmuur, so I could use it with nfnetlink enabled Snort_inline. Also the connection killing has been improved. The rules limit options were extended, to allow more flexibility.&lt;/p&gt;&#xA;&lt;p&gt;Second, with the great help of Adi Kriegisch, I&amp;rsquo;ve been working on setting up a new build server for Debian and Ubuntu packages. Credits mostly go to Adi, who did most of the work &lt;strong&gt;and&lt;/strong&gt; hosts the server. So many thanks to Adi! The new build server supports all version of Debian from Sarge up and of Ubuntu from Dapper and up.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Installing and creating Autopackages in a chroot</title>
      <link>https://inliniac.net/blog/2007/05/31/installing-and-creating-autopackages-in-a-chroot/</link>
      <pubDate>Thu, 31 May 2007 20:50:54 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/05/31/installing-and-creating-autopackages-in-a-chroot/</guid>
      <description>&lt;p&gt;This may be a little off-topic for this weblog, but since I spend quite some time researching this, I&amp;rsquo;ve decided to write about it anyway. When preparing a new release for Vuurmuur, I wanted to create an &lt;a href=&#34;http://www.autopackage.org&#34;&gt;Autopackage&lt;/a&gt; as well. For those that are unaware of it Autopackage is a distribution independent installer for Linux binaries. Because creating packages for every distro including flavor and versions is way out of my reach, a general installer can save the day.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur NFQUEUE support</title>
      <link>https://inliniac.net/blog/2007/05/22/vuurmuur-nfqueue-support/</link>
      <pubDate>Tue, 22 May 2007 13:21:23 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/05/22/vuurmuur-nfqueue-support/</guid>
      <description>&lt;p&gt;Vuurmuur supported the QUEUE target for a while already, even though it needed a little bit of a hack to handle the &lt;em&gt;state&lt;/em&gt;. This is because the iptables ruleset Vuurmuur creates is quite simple: after a few general protection rules it starts by accepting traffic with the state &lt;em&gt;established&lt;/em&gt;. Since there is no way to say &amp;lsquo;queue established traffic that was queued before&amp;rsquo; in iptables I decided to use traffic marking to distinguish between traffic to be queued or accepted. But there was a problem with this approach. I didn&amp;rsquo;t want to cripple the marking of traffic for other purposes, such as traffic shaping and routing, so I decided to use mark-ranges to either queue or accept:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur SVN now open</title>
      <link>https://inliniac.net/blog/2007/05/14/vuurmuur-svn-now-open/</link>
      <pubDate>Mon, 14 May 2007 16:57:09 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/05/14/vuurmuur-svn-now-open/</guid>
      <description>&lt;p&gt;For version control for Vuurmuur development I have been using Bazaar and Bazaar-NG. I&amp;rsquo;ve never really gotten used to Bazaar-NG. I admit that this is mostly due to lack of trying. For the Snort_inline project I have gotten used to Subversion, for which I even bought a book (Practical Subversion by Garrett Rooney, great book!). So recently I decided to move Vuurmuur also to SVN, for these three reasons:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;this way I need to work with only one tool&lt;/li&gt;&#xA;&lt;li&gt;people in the OSS community are more used to SVN so it&amp;rsquo;s easier for users and people interested in contributing&lt;/li&gt;&#xA;&lt;li&gt;Bazaar-NG doesn&amp;rsquo;t support SVN-style tags, except (I think) for the latest version which is not in my distro&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;So the SVN repository is now open. It is hosted at SourceForge at:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Experimenting with IPv6</title>
      <link>https://inliniac.net/blog/2007/03/13/experimenting-with-ipv6/</link>
      <pubDate>Tue, 13 Mar 2007 19:04:51 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/03/13/experimenting-with-ipv6/</guid>
      <description>&lt;p&gt;My &lt;a href=&#34;http://www.xs4all.nl/&#34;&gt;ISP&lt;/a&gt; is one of the few here in the Netherlands that provides a IPv6 tunnel broker. I have played with it some during the last year or so, but now decided to get a little more serious with it. So I&amp;rsquo;ve decided to enable it for my blog. When opening up my site to IPv6 one thing that is important is security. I will describe the status of IPv6 support of my current setup:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur developments</title>
      <link>https://inliniac.net/blog/2007/01/12/vuurmuur-developments/</link>
      <pubDate>Fri, 12 Jan 2007 21:47:01 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/01/12/vuurmuur-developments/</guid>
      <description>&lt;p&gt;This is my first blog post in 2007, so let me start by wishing everyone a good and healthy new year. In the new year I finally released a new version of Vuurmuur. It was the longest period between two releases, the last one was in April 06. The last year has been pretty hectic, with my graduation, looking for work, and now working&amp;hellip; Also I&amp;rsquo;ve been stepping up work on &lt;a href=&#34;http://snort-inline.sourceforge.net/&#34;&gt;Snort_inline&lt;/a&gt; and &lt;a href=&#34;http://www.inliniac.net/modsec2sguil/&#34;&gt;Modsec2sguil&lt;/a&gt;, which all took away coding time from Vuurmuur.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur: extending the connection options to the logviewer</title>
      <link>https://inliniac.net/blog/2006/10/01/vuurmuur-extending-the-connection-options-to-the-logviewer/</link>
      <pubDate>Sun, 01 Oct 2006 11:41:40 +0000</pubDate>
      <guid>https://inliniac.net/blog/2006/10/01/vuurmuur-extending-the-connection-options-to-the-logviewer/</guid>
      <description>&lt;p&gt;In Vuurmuur 0.5.72 alpha 1, I introduced a connection management interface to the connection viewer, allowing the administrator to kill connections and add ipaddresses to the blocklist. Next, I&amp;rsquo;m working on doing about the same for the logviewer. The idea is to have a menu with options for each individual logline. I can think of a large number of interesting options, but I think the best would be an option like &amp;lsquo;create a rule based on this logline&amp;rsquo;. This would then open a prefilled rule window based on the values in the log. This option would make it very easy to get going with a new Vuurmuur setup.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur: connection killing getting shape</title>
      <link>https://inliniac.net/blog/2006/09/02/vuurmuur-connection-killing-getting-shape/</link>
      <pubDate>Sat, 02 Sep 2006 13:26:28 +0000</pubDate>
      <guid>https://inliniac.net/blog/2006/09/02/vuurmuur-connection-killing-getting-shape/</guid>
      <description>&lt;p&gt;The main new feature of the 0.5.72 release of Vuurmuur will be the ability to kill existing connections from vuurmuur_conf. It will use the &lt;a href=&#34;http://www.netfilter.org/projects/conntrack/&#34;&gt;conntrack&lt;/a&gt; tool for this. Below is a screenshot of how it works.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2006/09/vuurmuur-kill-connection.png&#34; alt=&#34;Vuurmuur-conf killing a group of connections.&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Currently it works only for TCP connections and UDP pseudo connections. From the connection manager IPAdresses can also be added to the blocklist. All existing connections for this IP will be killed on that action. I have yet to extend this to hosts blocked manually.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur: first baby steps in traffic shaping</title>
      <link>https://inliniac.net/blog/2006/08/16/vuurmuur-first-baby-steps-in-traffic-shaping/</link>
      <pubDate>Wed, 16 Aug 2006 15:51:01 +0000</pubDate>
      <guid>https://inliniac.net/blog/2006/08/16/vuurmuur-first-baby-steps-in-traffic-shaping/</guid>
      <description>&lt;p&gt;Quite a while ago a placed a &lt;a href=&#34;http://wiki.vuurmuur.org/tiki/tiki-poll_results.php?pollId=3&#34;&gt;poll&lt;/a&gt; on the Vuurmuur Wiki, asking for the most important feature Vuurmuur needs. It turns out most people want traffic shaping. Traffic shaping has been on my todo list for a long time, but i never really got into using it, let alone understand it enough to integrate it into a GUI. So the last couple of days i had some spare time, and i have been checking it out. So far i am distinguishing the following types of traffic shaping.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vuurmuur: a new audit: passed</title>
      <link>https://inliniac.net/blog/2006/08/10/vuurmuur-a-new-audit-passed/</link>
      <pubDate>Thu, 10 Aug 2006 07:31:48 +0000</pubDate>
      <guid>https://inliniac.net/blog/2006/08/10/vuurmuur-a-new-audit-passed/</guid>
      <description>&lt;p&gt;Last week a user of Vuurmuur let me know he had another security audit at his work, and Vuurmuur passed without any remarks whatsoever. The auditors even said that this was quite unusual.&lt;/p&gt;&#xA;&lt;p&gt;The user is working in a Dutch company involved in stocktrading, and are forced to have the same level of security as their parent company, which is a bank. After the last time they had an audit, i added the auditlog feature to Vuurmuur, and it seems that has pleased them because unlike last time, they didn&amp;rsquo;t even complain about Vuurmuur&amp;rsquo;s &lt;em&gt;beta&lt;/em&gt; status ;-)&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
