APLawrence - Information and Resources for Unix and Linux Systems, Bloggers and the self-employed
RSS Feeds Get APLawrence.com by RSS











(OLDER) <- More Stuff -> (NEWER) (NEWEST)
Home > Book Reviews > Linux Firewalls Attack Detection and Response with iptables, psad and fwsnort
Printer Friendly Version






Linux Firewalls


2007/10/31

Index by Subject

  • 9781593271411
  • Prentice Hall
  • 9780132198576

graphic of book cover Order (or just read more about) Linux Firewalls  from Amazon.com

Although the introduction says "This book assumes some familiarity with TCP/IP networking concepts", it actually requires a pretty fair familiarity. Do not make the mistake of assuming that this is some cookie cutter approach that's going to teach you a bit about iptables and give you some scripts you can slap into place and forget. There are books that do that, but this isn't one.

The subtitle is "Attack Detection and Response with iptables, psad and fwsnort". Michael Rash is the author of psad, fwknop, and fwsnort among other things, so you can trust he knows what he's talking about here.



This is much more about learning how attackers try to get in and developing the countermeasures to keep them out. As everyone keeps reminding you, security is a journey, not a destination: you never get to "secure", you just work at it incessantly.

As such, this is a good book - I'm not sure it's a "great book" as the foreword proclaims, but then I'm probably too stingy with my superlatives. It's also possible that I'm simply not well versed enough in this area to appreciate greatness when it falls into my grubby little hands.

Nevertheless, I enjoyed this, and if you do know enough about networking to do a bit more than set your box to "Obtain an IP address automatically", you might enjoy it also. Michael Rash is the developer of the Dragon IDS and you'll find his website at http://www.cipherdyne.org/.

Video at http://www.youtube.com/watch?v=aDdq0u5xIME

Tony Lawrence 2007-10-31 Rating: 4.0


Technorati tags:
If this page was useful to you, please click to help others find it:  
Your +1's can help friends, contacts, and others on the web find the best stuff when they search.


1 comment




More Articles by Anthony Lawrence - Find me on Google+



Click here to add your comments





Thu Nov 1 13:55:29 2007:   BigDumbDinosaur


It's interesting you reviewed this book, as I've yet to find anything about iptables that is worth the paper on which it is printed. What I know about iptables was gleaned from a painful discovery process, not by consulting some well-written tome (there aren't any on the subject).

Unfortunately, in the world of Linux, crappy documentation is the norm. For all the work and talent that has been applied to the OS itself, I'm amazed at how poorly it has been documented. Many man or info pages are an incomplete mess or are entirely missing. In some cases, man pages are obviously the product of someone who far more an expert at writing code than English prose. This whole situation is ironic, given that RTFM is often the response given to a newbie by Linux veterans. How do we expect anyone to RTFM when there isn't anything to read or what is available is incomplete?

Don't miss responses! Subscribe to Comments by RSS or by Email

Click here to add your comments


If you want a picture to show with your comment, go get a Gravatar


Kerio Connect Mailserver

Kerio Control Firewall

Have you tried Searching this site?

Unix/Linux/Mac OS X support by phone, email or on-site: Support Rates

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more. We appreciate comments and article submissions.

Publishing your articles here

Jump to Comments



Many of the products and books I review are things I purchased for my own use. Some were given to me specifically for the purpose of reviewing them. I resell or can earn commissions from the sale of some of these items. Links within these pages may be affiliate links that pay me for referring you to them. That's mostly insignificant amounts of money; whenever it is not I have made my relationship plain. I also may own stock in companies mentioned here. If you have any question, please do feel free to contact me.

Specific links that take you to pages that allow you to purchase the item I reviewed are very likely to pay me a commission. Many of the books I review were given to me by the publishers specifically for the purpose of writing a review. These gifts and referral fees do not affect my opinions; I often give bad reviews anyway.

We use Google third-party advertising companies to serve ads when you visit our website. These companies may use information (not including your name, address, email address, or telephone number) about your visits to this and other websites in order to provide advertisements about goods and services of interest to you. If you would like more information about this practice and to know your choices about not having this information used by these companies, click here.


My Troubleshooting E-Book will show you how to solve tough problems on Linux and Unix systems!


book graphic unix and linux troubleshooting guide




Buy Kerio from a dealer who knows tech: I sell and support

Kerio Connect Mail server, Control, Workspace and Operator licenses and subscription renewals
pavatar.jpg

This post tagged:

       - Books
       - Linux
       - Reviews
       - Security
       - Unix




Unix/Linux Consultants

Skills Tests

Guest Post Here