question about firewall on linux daily driver

d3athf1sh

[H]ard|Gawd
Joined
Dec 16, 2015
Messages
1,476
ok so i got my parents computer switched over to linux (đź–•widows11). ended up going with a windows themed version of Q4OS (debian). well the original project was called XPQ4 for people that still wanted an XP like experience, well i experimented with both and ended up with the updated win10 like version. ** for anyone interested>> https://xpq4.sourceforge.io

but my question is, i've noticed on most of the distro's i've been messing with all come with a firewall but it's always disabled by default. is that something that should be activated and if so what about with older people that aren't very computer savy like us and really only use it to pay bills, book plane tickets, email, amazon etc etc. also, there's a firewall enabled on the router which is fairly new (802.11ax) so if the one in linux machine is just gonna constantly be pinging notifications like zone alarm use to do i'm just going to leave it disabled anyway.

any input would be appreciated.
 
I use OpenSnitch, which works quite well like Zone Alarm.

You will need to configure default actions & how it deals with new apps (new versions of same apps, too).
 
Your router's firewall should be good enough, generally, a local firewall really only keeps malicious programs on your PC from dialing out or receiving communications from other malicious programs on your network, which in general shouldn't be an issue (unless you are running scripts and programs which are untrusted/unverified, especially as root).

On ArchLinux, I've been using firewalld. There's a graphical configuration utility, but I forget whether it's packaged together or in a separate. NetworkManager integrates with it too. You can select ports to enable/disable for common services or make your own rules.

Alternatively, you can adjust nftables rules yourself (that's what firewalld does for you), but I like the convenience it provides.

Edit "GUI is available as firewall-config which comes with firewalld package," but in your distro it may be packaged separately. Some distros are funny like that.
 
Last edited:
Your router's firewall should be good enough, generally, a local firewall really only keeps malicious programs on your PC from dialing out or receiving communications from other malicious programs on your network, which in general shouldn't be an issue (unless you are running scripts and programs which are untrusted/unverified, especially as root).

On ArchLinux, I've been using firewalld. There's a graphical configuration utility, but I forget whether it's packaged together or in a separate. NetworkManager integrates with it too. You can select ports to enable/disable for common services or make your own rules.

Alternatively, you can adjust nftables rules yourself (that's what firewalld does for you), but I like the convenience it provides.
Router firewall is NOT good enough for old people, they always find a way to get shit on their computer.
 
Your router's firewall should be good enough, generally, a local firewall really only keeps malicious programs on your PC from dialing out or receiving communications from other malicious programs on your network, which in general shouldn't be an issue (unless you are running scripts and programs which are untrusted/unverified, especially as root).

On ArchLinux, I've been using firewalld. There's a graphical configuration utility, but I forget whether it's packaged together or in a separate. NetworkManager integrates with it too. You can select ports to enable/disable for common services or make your own rules.

Alternatively, you can adjust nftables rules yourself (that's what firewalld does for you), but I like the convenience it provides.

Edit "GUI is available as firewall-config which comes with firewalld package," but in your distro it may be packaged separately. Some distros are funny like that.
firewalld is pretty good.

I just use ufw across my systems and servers. There is a GUI for it gufw if you so desire. I typically only allow SSH, 80 and 443, and whatever ports I need open for my self-hosted tools.
 
Router firewall is NOT good enough for old people, they always find a way to get shit on their computer.
Thankfully most people in India walking them through remote desktops hang up in annoyance when they realize there on Linux.
In general though ya if your distro has a firewall it doesn't hurt to take a few minutes and set it up. Shouldn't be to much messing around for people just wanting to be able to use the internet.
 
ok so i got my parents computer switched over to linux (đź–•widows11). ended up going with a windows themed version of Q4OS (debian). well the original project was called XPQ4 for people that still wanted an XP like experience, well i experimented with both and ended up with the updated win10 like version. ** for anyone interested>> https://xpq4.sourceforge.io
Oh man here I was trying to theme Ubuntu to look like windows XP when there is an entire distro built around doing exactly that, that is so cool!

I've moved on and am now trying to rice my hyprland set up to mimic windows XP, from the taskbar and background aspect anyway. I love dynamic window managers too much to go back now.
 
just thought i'd give an update since i went to my parents today and looks like the firewall that came included with the OS is G-UFW. so it was as simple as turning it and was already set to allow outgoing and block all incoming. man i think that OS is actually pretty great and prob the closest thing to using windows as you can get, even more so than zorin. heck i'd probably be inclined to use it myself if i wasn't a gamer. heck you prob could set it up to game, but why when there are already OS's setup for gaming out of the box?

but anyway problem solved. thanks for all the input!
 
  • Like
Reactions: ChadD
like this
Router firewall is NOT good enough for old people, they always find a way to get shit on their computer.
a firewall alone wont stop this, even using safe DNS like OpenDNS or Cloudflare wont stop someone fully finding a malicious link and clicking on something.
 
Cloudflare Family w/ Malware blocking might go pretty far but I never just stop with such
Another idea is to go with an online option like NextDNS or Adguard DNS & then share out the customized DNS address
 
Wow, I've been using Linux for years and never gave the firewall a thought. Just checked mine and yup, it's off. Since I've never seen a need for one, it will stay off.
 
WOW, switching your parent over to Linux is brave. You should be given an award for that. kudos to you young man.
 
I think my question is related, so trying to save from starting a new thread.

I am a Linux novice. I was inspired by my director who recently told me that his whole house is only Linux machines.

I'm worried about Win10 being out of support and don't want to get a Win11 PC right now. I plan to keep my Win 10 desktop for gaming, for now.

I ordered a laptop with Linux Mint installed, and I'm going to use it for all of my financials once it arrives.

I'm wondering what browser would be "safest" for this purpose. I'm used to Chrome, but I figure that one gets attacked the most. Is Chrome any safer on Linux, or is it still dangerous? Should I use Firefox, Brave, or something else?
 
I think my question is related, so trying to save from starting a new thread.

I am a Linux novice. I was inspired by my director who recently told me that his whole house is only Linux machines.

I'm worried about Win10 being out of support and don't want to get a Win11 PC right now. I plan to keep my Win 10 desktop for gaming, for now.

I ordered a laptop with Linux Mint installed, and I'm going to use it for all of my financials once it arrives.

I'm wondering what browser would be "safest" for this purpose. I'm used to Chrome, but I figure that one gets attacked the most. Is Chrome any safer on Linux, or is it still dangerous? Should I use Firefox, Brave, or something else?
All I can do is tell you what I use and how. First of all I don't use Chrome and never have. I hated it from the first time I installed it when it was new.

For the vast majority of my usual browsing, including banking and such, I use Vivaldi. No special security reason but because it's user configurable to a great extent (the developer is one of the original Opera devs before it was sold to China) and it works great for me. It's rare I have an issue with a website and it's a Chromium based browser. I do not have an ad blocker installed with this browser. Most of the sites I'm likely to visit aren't obnoxious with ads (with the exception of Phoronix) and I'm not against sites I visit frequently to gain some ad revenue from my frequent visits.

The second browser I use is Brave. This is mostly for streaming use such as Youtube and Rumble due to the built in ad blocking. It's also nice for using on websites with horrendous ads and it's my backup in case a site doesn't play well with Vivaldi. It is also Chromium based.

I don't particularly use it often but I also have Firefox installed. It's mostly just a backup for the backup especially since it uses its own browsing engine and not based on Chromium. There have been occasional issues with sites with the other two browsers which didn't occur with Firefox. Normally this is because the morons coding the site only test it against Chrome and the site isn't following standards. Pretty sure I have an ad blocker installed with Firefox but couldn't tell you which one it is.

Be aware that all three of these browsers have privacy controls built in. It's probably a good idea to use some of them but no matter which browser it is if the privacy controls are too strict it will cause havoc with a number of sites. Just have to fiddle with things if you want.

An option that is out there which I don't use it Chromium itself. It's basically Chrome with most of the google stuff removed. There's probably something called chromium ungoogled or something similar in the package manager which should have basically all the google stuff torn out. I've never used Chromium or the ungoogled Chromium so I can't comment on either one.
 
Personally, I've never enabled the firewall and I've never had a problem. I tend to block certain protocols running IPv6 at the firewall of my router, I've never really found it necessary to have the same functionality under my OS.
 
I always enable the firewall and use the default block all inbound, but outbound is wide open. Why not add a free layer of protection to block anything incoming that should not? Especially if a laptop and you might use it in places outside of your own network.

As for browsers most are safe, but like others, I am a Brave / Librewolf main user now as they just do not collect and sell your data like Chrome or Edge does...
 
Wow, I've been using Linux for years and never gave the firewall a thought. Just checked mine and yup, it's off. Since I've never seen a need for one, it will stay off.
There is no harm in blocking Incoming. If you are not hosting anything on your system..

Now many think "Well if they are on my network I already have bigger problems" sure, but at least with your device blocking all inbound by default, network scans wont find your device...
 
There is no harm in blocking Incoming. If you are not hosting anything on your system..

Now many think "Well if they are on my network I already have bigger problems" sure, but at least with your device blocking all inbound by default, network scans wont find your device...
Well, if it's blocking, they'll see your system send the response. If it's dropping, then it won't be seen.
 
Just checked mine with the intentions of turning it on and it was already on. An update musta done it because I didn't.
 
Back
Top