Jump to content
Not connected, Your IP: 3.145.186.173
keikari

Does network lock work like really strict firewall?

Recommended Posts

Hi, I'm trying to learn basics of understanding how to set up/use firewall. I started wondering would my system be safe if I didn't had any other firewall rules than ones the network lock creates? And if not, why?

Also bit out of topic, but is there any reason to favor firewalld over iptables? Or is it just created to make things simpler? And if I want to configure firewall with iptables are there any important differences in running firewalld.service or iptables.service?

Share this post


Link to post

As you are referencing to iptables, i assume you are using a Linux based OS.

Yes, with network lock enabled you are safe even without an additional firewall (UFW for example).
Network lock is based on IP Tables; it works in a proactive way, preventing traffic from leaking outside of the VPN tunnel. So with Network Lock enabled an no VPN connection --> no Internet.

It is unlike an ordinary "Kill Switch" that just reacts when the VPN connection drops.

Of course you can make your own firewall by creating iptables or UFW rules, but personally i wouldn't use UFW/iptables  along with Network Lock, just to prevent any possible interferences.

Regards

BB


AMD Ryzen 3950X @ 105W PPL

Gigabyte X570 Aorus Elite

AMD RX 5700 XT

Corsair DDR4-3200 32GB

 

Share this post


Link to post

Do both, that is what I do.  I will avoid the technical "how to" but its really easy to do.  With 2 posts I don't know where you are on abilities to write simple UFW firewall rules.  I use Eddie on several linux family machines.  I set up totally internet blocked firewalls on these machines.  Eddie running on the linux Desktop (Debian) will create its own firewall when its launched and will TEMPORARILY store my UFW firewall as a backup (done automatically in the background).  When I close Eddie MY original firewall rules are reset so that my machines cannot ever access the internet under any circumstances without an AirVpn tunnel.  For my machines this additional safety measure means that a family member cannot mount the computer and then go online while being outside an AirVpn tunnel.  They have no clue or desire to learn how to mount UFW in a terminal and disable the firewall manually.  They have learned to click on the AirVpn Icon on the Desktop and then enter the Admin password to launch it.  I have Eddie set to auto connect to the desired server so they just sit there and enjoy an easy connection and safe surfing.  So simple and compels their security whether the want it or not, LOL!!

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image

×
×
  • Create New...