store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 8:10 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic This topic is locked, you cannot edit posts or make further replies. Share/Bookmark  [ 1 post ] 
Author Message
 Post subject: [asl-3.0] ASL 3.0.25 Update
Unread postPosted: Tue Jun 19, 2012 3:13 pm 
Online
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Release Notes:
This update contains the beta version of the Fast-Mode firewall system. We called it "Fast" because its fast.. real fast. Previous firewalls could take minutes or even hours to load large rulesets, the ASL Fast-Mode firewall will load hundreds of thousands of rules in seconds.

Features:
* Its fast. Real Fast.
* Inbound TCP services list (FW_INBOUND_TCP_SERVICES)
* Inbound UDP services list (FW_INBOUND_UDP_SERVICES)
* Outbound TCP services list (FW_OUTPUT_TCP_SERVICES)
* Outbound UDP services list (FW_OUTPUT_UDP_SERVICES)
* Dshield, Lasso, and TOR blacklists (FW_DSHIELD, FW_LASSO, FW_TOR)
* Faster (real fast!) loading of existing blacklist/geo-blacklist sets
* User ID limited firewall rules for SMTP traffic from the ACL list /etc/asl/firewall/mta-output-acl. When enabled, only users on this list will be able to connect to external mail servers, preventing untrusted web users from bypassing the internal MTA through the use of spam bots.
* Tortixd ACL list (/etc/asl/firewall/tortixd-access-list), when enabled this is a list of IP's allowed to connect to the ASL Web interface
* Support for user defined rules through ASL Web
* All rules are moved to named ASL- chains.

As a beta component, new features introduced the ASL Fast-Mode firewall are disabled by default. Existing components from the legacy ASL firewall such as the geo-blacklist will take advantage of the new fast-mode loading capabilities with no additional configuration required. While we took pains to make the ASL Fast-mode firewall compatible with other rule management interfaces, we recommend removing or otherwise disabling other firewall management systems. Therefore, third party firewall management tools are not supported.

Changelog:
- Add Fast-Mode firewall system
- Add New monitoring capabilities added: load, diskspace and listeners
- Update, T-WAF, force fix mode if tortix_waf.conf is not detected
- Update, ASL Web, firewall rule changes are saved across reboots
- Update, Configuration, mysql administrator username defaults to "root"
- Update, File integrity, add aqueduct directories to ignores
- Feature Request #628, Add MTA firewall rule group (/etc/asl/firewall/mta-output-acl)
- Bugfix #XXX, ASL Web, Fixes issues with rule edit in firewall window
- Bugfix #XXX, firewall, detect /proc based controls more accurately
- Bugfix #XXX, add more redundancy to waf/tortix proxy configs. This will now purge old versions when configs are blank, in addition to linting configs when they are not blank
- Bugfix #XXX, only write to file if $waf_redirect has something in it
- Bugfix #XXX, ssh_check, fix for enabling password auth when ADMIN users are not defined
- Bugfix #XXX, asl-firstboot, fix path for asl-firstboot's network info file, and add in a post-success cleanup event

To Upgrade:
1) asl -u

or
yum upgrade asl asl-web asl-waf-module

2) reload your firewall rules:

service iptables restart
service asl-firewall restart


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic This topic is locked, you cannot edit posts or make further replies. Share/Bookmark  [ 1 post ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group