Firewall on a labtop as private web / mail server

Patrick Serru <[email protected]> Tue, 3 Oct 2017 10:40:50 -0500
Newsgroups gmane.linux.suse.security
Message-ID <201710031040.50118@----Apocryphe---->
    Hello everyone,

    I hope I am asking on the good list. Excuse me, please, if not.

    This is strange, but on the 5 Leap 42.3 installations on a labtop Compaq 
Presario C700, the last two did me the honor to ask me the configuration of 
the network, and not the first three. Can anyone tell me, please, why the 
installation may require configuration, immediately after the choice of 
language and layout of the keyboard ? The choice of a minimal installation, 
perhaps.

    After this minimal installation for a text-based operation, online 
updating, adding to the minimum system of XOrg-X11 and tigervnc, having 
banned the "yast2-firewall" and "network manager" packages, the system 
reboots and works correctly, with wifi interfaces and Ethernet still in the 
desired configuration.

    Here is a shema of installation :
      ____   eth0             ____
     |    |<---------------->|    |
     |desk|              .-->|hub |
     |top |  eth1        |   |    |
     |____|<--.          |   |____|
              |          | 192.168.0.0      ______
         eth1 |          |    _____       _/      \_
  198.168.1.0 |          .-->|     |     (          )
              |              |modem|---->( INTERNET )
         eth0 |              |cable|     (_        _)
      ____    |              |_____|       \______/
     |    |<--’ eth0            ^
     |lab |                     |
     | top| wlan0               . 192.168.0.0
     |____|<--....           ....

    Can anyone help me, please, to set up the labtop firewall, with the
file /etc/sysconfig/SuSEfirewall2 ? Here is the contents of this file for my 
last attempt:
FW_DEV_EXT="wlan0"
FW_DEV_INT="eth0"
FW_DEV_DMZ=""
FW_ROUTE="no"
FW_MASQUERADE="no"
FW_MASQ_DEV=""
FW_MASQ_NETS=""
FW_NOMASQ_NETS=""
FW_PROTECT_FROM_INT=""
FW_SERVICES_EXT_TCP="http https 587 imap"
FW_SERVICES_EXT_UDP="53"
All other parameters contain their default values (either empty,
or empty strings).

    My goal is to allow all the traffic on the network 192.168.1.0 (eth0) and 
limit that from the outside (wlan0) to http, https, 587 and imap. The labtop 
must of course be able to resolve domain names (DNS).

    I thank you for the attention you paid ti this e-mail.

    Sincerly,

Patrick Serru
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]