You are not logged in.

#1 2017-03-30 09:32:32

onny
Member
From: Europe
Registered: 2010-08-07
Posts: 46
Website

Application firewall Douane for ArchLinux

Hey,
I found out about the application firewall Douane and updated to AUR packages and it seems to be working again smile
You have to install a kernel module, a daemon and a user space tool to use this. After running everything, Douane asks for permission as soon an application tries to connect to the internet.

https://project-insanity.org/wp-content … 20x379.png

Further installation instructions can be found in my blog post here: https://project-insanity.org/blog/2017/ … archlinux/

What do you think about it? Do you know any alternatives?

Regards,
Jonas

-- mod edit: converted img to url tags.  Trilby --

Last edited by Trilby (2017-03-30 10:44:10)

Offline

#2 2017-03-30 09:58:02

Awebb
Member
Registered: 2010-05-06
Posts: 6,285

Re: Application firewall Douane for ArchLinux

Alternatives? Don't install stuff on your system you don't trust. Promoting "personal firewalls" is a good way to turn your blog promotion into a reason to filter your URL against accidental visits. Quiz: Which board rule did you just break?

Offline

#3 2017-03-30 10:51:45

Trilby
Inspector Parrot
Registered: 2011-11-29
Posts: 29,523
Website

Re: Application firewall Douane for ArchLinux

I have no background with which to judge the above-scare-quoted "personal firewalls", but in terms of forums rules I only see one that was clearly broken, but another that is iffy.

Onny, please see the forum guidelines on posting images.  In short: don't.  Post links to images, or at most small (250x250 or smaller) thumbnails.

Also see the rules about advertising a personal blog.  There is some grey area here especially in community contributions: when you make something you might share it with the world via a blog, then share it here too and link to the blog.  In this way a blog can bit a bit like a github or other repository page which we do allow sharing links to.

That said, this would be a much better contribution to the community if it were in a wiki page on our wiki.  I don't see any douane entries on our wiki.  This would allow the content to be reviewed, updated, and available well into the future for other users.

I see you've previously contributed to the wiki, but your last to Community Contribution posts instead link to your blog - you are moving in the wrong direction, please adjust your course.  Continued posting of links to your blog will not be given so much leeway.


"UNIX is simple and coherent..." - Dennis Ritchie, "GNU's Not UNIX" -  Richard Stallman

Offline

#4 2017-03-30 10:51:59

Docbroke
Member
From: India
Registered: 2015-06-13
Posts: 1,433

Re: Application firewall Douane for ArchLinux

Offline

#5 2017-03-30 13:14:03

progandy
Member
Registered: 2012-05-17
Posts: 5,190

Re: Application firewall Douane for ArchLinux

Do you know any alternatives?

You can probably use a kernel security module that implements access control like grsecurity or selinux, and only grant select applications access to certain sockets/ips/... . You won't have a convenient GUI with permission requests, though.

Last edited by progandy (2017-03-30 13:18:03)


| alias CUTF='LANG=en_XX.UTF-8@POSIX ' |

Offline

#6 2017-03-31 01:25:36

0strodamus
Member
Registered: 2014-01-22
Posts: 92

Re: Application firewall Douane for ArchLinux

onny wrote:

Do you know any alternatives?

This forum posting inspired me to use TOMOYO Linux as an application firewall. I use a default policy group as outlined in the forum post to block all applications from accessing the network and another policy group to further restrict my web browsers, email programs, etc.

Thanks for uploading Douane to the AUR.


archlinux | OpenRC | TOMOYO Linux | Xfce

"In his house at R'lyeh dead Cthulhu waits dreaming."

Offline

Board footer

Powered by FluxBB