<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title><![CDATA[GUI for ufw (Uncomplicated Firewall)]]></title>
    <link>http://brainstorm.ubuntu.com/item/22/</link>
    <description><![CDATA[It would be useful to create a graphical user interface for the new ufw (Uncomplicated Firewall) in Ubuntu. Would be useful to make every new release with an enabled firewall by default and with this graphical firewall utility also.<br />
<br />


<b>[1615 votes] Solution #1: Auto-generated solution of idea #22</b>
<br />

<br />
<br />



]]></description>

    <language>en-us</language>
    <pubDate>Thu, 28 Feb 2008 14:43:07 +0000</pubDate>
    <lastBuildDate>Fri, 23 Oct 2009 06:38:44 +0000</lastBuildDate>
    <generator>QAPoll module</generator>
    <guid isPermaLink="true">http://brainstorm.ubuntu.com/idea/22/</guid>
        <item>
  <title>Comment from zelut</title>
  <description><![CDATA[ufw is supposed to be very simple in a CLI environment.  There are already many graphical interfaces for firewalling utilities such as Firestarter, etc.]]></description>
  <pubDate>Thu, 28 Feb 2008 15:43:07 +0000</pubDate>
</item>
        <item>
  <title>Comment from arzajac</title>
  <description><![CDATA[There is no need for a firewall on a desktop system.<br /><br />By default, nothing listens to the network.  If you need to install something that does, you will have to open up your firewall anyway.  It's a waste of time and a false sense of security.<br />]]></description>
  <pubDate>Thu, 28 Feb 2008 18:31:37 +0000</pubDate>
</item>
        <item>
  <title>Comment from Phase</title>
  <description><![CDATA[except, when a trojan opens a port but do not modify the ruleset or ... <br /><br />anyway - a firewall system is no waste of time ...]]></description>
  <pubDate>Thu, 28 Feb 2008 23:49:36 +0000</pubDate>
</item>
        <item>
  <title>Comment from defcon</title>
  <description><![CDATA[I agree with this feature, some people will need to open certain ports for certain applications, and may want to block certain applications from certain ip ranges.  Add a few nice features in an easy/basic gui and a firewall log monitor and we will see allot of happy people.]]></description>
  <pubDate>Fri, 29 Feb 2008 02:31:11 +0000</pubDate>
</item>
        <item>
  <title>Comment from bluecat9</title>
  <description><![CDATA[I'm not positive but I think a similar idea is on paper for the release after Hardy... (simple firewall)]]></description>
  <pubDate>Fri, 29 Feb 2008 03:22:37 +0000</pubDate>
</item>
        <item>
  <title>Comment from Vadim P.</title>
  <description><![CDATA[Yes, but it'll be terminal-only.]]></description>
  <pubDate>Fri, 29 Feb 2008 05:30:02 +0000</pubDate>
</item>
        <item>
  <title>Comment from jelly1</title>
  <description><![CDATA[It would be nice if there was a simple GUI firewall for noobs and people how don;t have the time to learn iptables etc. Firestarter is a good one, why doesn't it come to ubuntu by default?]]></description>
  <pubDate>Fri, 29 Feb 2008 10:57:10 +0000</pubDate>
</item>
        <item>
  <title>Comment from azrael</title>
  <description><![CDATA[The following wiki page explains the scope of ufw:<br />https://wiki.ubuntu.com/UbuntuFirewall<br />For now I don't see any plans for a GUI.]]></description>
  <pubDate>Fri, 29 Feb 2008 12:46:58 +0000</pubDate>
</item>
        <item>
  <title>Comment from jeanpaul145</title>
  <description><![CDATA[Quite frankly, I'm a bit shocked that there isn't already a GUI frontend for UFW.<br />What's the point in creating an "easy-to-use" CLI frontend for iptables if most if the users are a bit shy around that very same CLI?]]></description>
  <pubDate>Fri, 29 Feb 2008 21:04:40 +0000</pubDate>
</item>
        <item>
  <title>Comment from adelie</title>
  <description><![CDATA[This is more of an issue with 'other operating systems', and once you need a tool like this in Gnu / Linux, I would doubt you would want just some little GUI to do it for you.]]></description>
  <pubDate>Fri, 29 Feb 2008 22:09:32 +0000</pubDate>
</item>
        <item>
  <title>Comment from rawsausage</title>
  <description><![CDATA[If I may say, nice work but moot. I've run 100% non-firewalled Windows XP on 10mbit copper connection 24/7 for couple years. Not one single security problem. I have run non-firewalled Linux for years. It's a storm out there but it does not do a thing. Why? There are two very simple reasons. First of all, firewalls affect the symptoms and not the reasons of security problems. Manage your platform well (updates, sane configuration etc) and you have managed the reasons. Second, if you have a vulnerability in some daemon or like you will be opening most likely a hole for it anyways - making the firewall in most cases useless anyways. On top of that firewalls break easily intented network usage and provide a huge potential common point of failure. In the end of the day firewalls do NOT belong on simple desktops at all.]]></description>
  <pubDate>Fri, 29 Feb 2008 22:39:26 +0000</pubDate>
</item>
        <item>
  <title>Comment from omegamormegil</title>
  <description><![CDATA[arzajac is correct when he said: <br /><br />"There is no need for a firewall on a desktop system.<br /><br />By default, nothing listens to the network. If you need to  install something that does, you will have to open up your firewall anyway. It's a waste of time and a false sense of security. " <br /><br />So, perhaps all that would be needed is a gui which displays what ports are open, because of software you've installed on the system, along with the option of closing the ports (thus disabling the connectivity of the software) or uninstalling the package opening the port.  <br /><br />Complicated rules aren't needed, because everything is closed by default, but it would be nice to know what is open without having to run nmap on yourself.  ]]></description>
  <pubDate>Fri, 29 Feb 2008 22:52:10 +0000</pubDate>
</item>
        <item>
  <title>Comment from defcon</title>
  <description><![CDATA[I would personally prefer an easy to use Gnome Panel Applet, a full application is unneeded.  Although both would be awesome!]]></description>
  <pubDate>Sat, 01 Mar 2008 07:06:44 +0000</pubDate>
</item>
        <item>
  <title>Comment from smejky</title>
  <description><![CDATA[I would like to see a GUI written in PyGTK.]]></description>
  <pubDate>Sun, 02 Mar 2008 14:07:43 +0000</pubDate>
</item>
        <item>
  <title>Comment from gabim</title>
  <description><![CDATA[Yes, it is right, the ufw is supposed to be very simple in a CLI environment and there are not any plans for a GUI.<br /><br />But, the ufw is so uncomplicated and so clear that it is suitable for the basis of a good graphical firewall for the Ubuntu. It is so revolutionary (as the Ubuntu also) that the graphical user interface is a must have feature for the ufw.<br /><br />It is a big mistake to say there is not any need for a default, enabled, built-in firewall because "by default, nothing listens to the network" and because "this is a desktop system".<br /><br />The newly installed system is not in the state "by default" for a long time, because the user begins to use it and install it and configure it. Installs some server applications (e.g. Apache or MySQL), installs some peer to peer applications (e.g. torrent clients) and so on. This is absolutely normal on a Linux desktop nowadays, he/she does not want to build a server, just a personalized functional desktop system. And at this moment, there is a new situation by the installation of these applications: many uncontrolled open ports. From this moment on we can interpret the built-in enabled firewall as a useful feature which can help to keep the desktop system secure. And the well designed GUI helps to keep the necessary firewall rules up to date and well designed for the daily purposes.<br />]]></description>
  <pubDate>Mon, 03 Mar 2008 15:18:31 +0000</pubDate>
</item>
        <item>
  <title>Comment from arzajac</title>
  <description><![CDATA[>And at this moment, there is a new situation by the >installation of these applications: many uncontrolled open >ports. <br /><br />How do you define uncontrolled?  <br /><br />When you install an application, it should work.  You should not need to disable a port as an extra step.  And if you are simply running an application like apache for example, that doesn't make your system more vulnerable in of itself.<br /><br />The user may very well make the computer vulnerable, but a firewall will not prevent that.  The very same user who would install an insecure web application on top of apache will nonetheless open the port.  A firewall won't stop that.<br /><br />You should be able to install and configure a firewall if you need/want to, but it should not be there by default.<br /><br />>From this moment on we can interpret the built-in enabled >firewall as a useful feature which can help to keep the >desktop system secure. <br /><br />If you think that a firewall is keeping you safe, you are mistaken.  A firewall is easily avoided by either the user or the malicious software exploit.<br /><br />And malicious code does not install itself on your computer through open ports like that.  You are not putting the Ubuntu Desktop user at risk by not including a firewall by default.<br /><br />]]></description>
  <pubDate>Mon, 03 Mar 2008 18:34:24 +0000</pubDate>
</item>
        <item>
  <title>Comment from gabim</title>
  <description><![CDATA[Here are some articles in the "justification of a firewall on the desktop workstation" topic, the reasons are written well in them.<br /><br />Desktop Security Guidelines: http://its.unm.edu/security/dsg.html<br />It’s only a workstation: http://www.scmagazine.com/asia/news/article/419677/consultants-view-its-workstation/<br />Why You Need a PC Firewall: http://www.zonealarm.com/store/content/support/zasc/whyFirewall.jsp<br />]]></description>
  <pubDate>Tue, 04 Mar 2008 08:37:14 +0000</pubDate>
</item>
        <item>
  <title>Comment from arzajac</title>
  <description><![CDATA[Those links are not very informative, and are geared towards the sale of firewall software.<br /><br />Here are some useful links regarding software firewalls:<br />http://www.securityfocus.com/infocus/1839<br />http://www.securityfocus.com/infocus/1840]]></description>
  <pubDate>Tue, 04 Mar 2008 17:02:46 +0000</pubDate>
</item>
        <item>
  <title>Comment from Eldmannen</title>
  <description><![CDATA[UFW is a Python script for iptables.]]></description>
  <pubDate>Fri, 07 Mar 2008 01:14:56 +0000</pubDate>
</item>
        <item>
  <title>Comment from Eldmannen</title>
  <description><![CDATA[What you really want is a GUI for iptables.]]></description>
  <pubDate>Fri, 21 Mar 2008 00:21:29 +0000</pubDate>
</item>
        <item>
  <title>Comment from guyome</title>
  <description><![CDATA[In fact, we want a graphical interface to manage firewall on Ubuntu. The development of Firestarter is very slow and it's not easy to use it with Vpn, for example. <br /><br />It would be a great feature to have an GUI who's as efficient as iptables...]]></description>
  <pubDate>Sun, 23 Mar 2008 16:39:28 +0000</pubDate>
</item>
        <item>
  <title>Comment from fibrewire</title>
  <description><![CDATA[Can someone outline the pro's and con's of having a firewall, and back up the statements with references? I would but i would most likely produce biased results - as well as including IDS or IPS or whatever its name is these days...]]></description>
  <pubDate>Mon, 24 Mar 2008 18:29:33 +0000</pubDate>
</item>
        <item>
  <title>Comment from fibrewire</title>
  <description><![CDATA[Can someone outline the pro's and con's of having a firewall, and back up the statements with references? I would but i would most likely produce biased results - as well as including IDS or IPS or whatever its name is these days...  what about integrating "Untangle" into ubuntu server and the IDS/IPS system into ubuntu desktop?  Its all GPL'd software - Untangle could stand an interface rewrite to be more like CISCO equipment, and i hate cisco!]]></description>
  <pubDate>Mon, 24 Mar 2008 18:44:00 +0000</pubDate>
</item>
        <item>
  <title>Comment from Adrian Godoy</title>
  <description><![CDATA[I use guarddog for KDE on Gnome. It works fine. I think the gui is very intuitive. I would like to see something similar for ufw. Ufw seems to be very simple from the command line. I will have to take it for a test drive.]]></description>
  <pubDate>Mon, 07 Apr 2008 22:50:08 +0000</pubDate>
</item>
        <item>
  <title>Comment from drinkypoo</title>
  <description><![CDATA["Can someone outline the pro's and con's of having a firewall, and back up the statements with references?" what is this, are we doing your homework for you? Pros: security. Cons: you have to manage it. What more do you need to know? <br /><br />Anyway I just want to say that this is a super-silly suggestion. ufw is an interface to iptables. What we need is a more convenient interface to iptables. Firestarter is inadequate because it can only handle two interfaces tops, one inside and one outside, due to its fundamentally primitive design (of the GUI.) I would propose something based on the ipmasq package, or something totally new.<br /><br />I manage my firewall with fwbuilder but this is too advanced for most users.]]></description>
  <pubDate>Thu, 08 May 2008 16:01:09 +0000</pubDate>
</item>
        <item>
  <title>Comment from deejross</title>
  <description><![CDATA[UFW is itself a frontend for iptables. And there's already several GUI's for iptables. Firestarter works pretty well. But most likely, you will be using a firewall on a server machine where there is no desktop, and therefore, no gui...hence the need for a simple, text-based frontend for iptables...ufw.]]></description>
  <pubDate>Tue, 13 May 2008 14:55:39 +0000</pubDate>
</item>
        <item>
  <title>Comment from jdevora</title>
  <description><![CDATA[Why not???<br /><br />Answered in "Why ufw Does Not Need A GUI" : <br />http://ubuntu-tutorials.com/2008/05/04/why-ufw-does-not-need-a-gui/]]></description>
  <pubDate>Thu, 15 May 2008 18:02:18 +0000</pubDate>
</item>
        <item>
  <title>Comment from marquinos</title>
  <description><![CDATA[Hello.<br />I made a simple GUI in Python + Glade.<br />You can download it at:<br />http://code.google.com/p/gui-ufw/<br />To install follow the instructions of the file installation.<br />A greeting.]]></description>
  <pubDate>Tue, 27 May 2008 14:43:13 +0000</pubDate>
</item>
        <item>
  <title>Comment from Vadim P.</title>
  <description><![CDATA[Wow, very nice. Thank you]]></description>
  <pubDate>Thu, 12 Jun 2008 00:04:36 +0000</pubDate>
</item>
        <item>
  <title>Comment from TrAndy</title>
  <description><![CDATA[Intro<br />-----<br />Yes, Windoze users would like to see this as X only users too.<br />I'm neither the first nor the latter, anyway because an X environment has been present since the early times of Linux, it is correct to be coherent with.<br />Real GUI environments shouldn't require the use of the keyboard (as far as it makes sense).<br /><br />To the facts<br />------------<br />Please, and I underline, Please!, make the GUI IPv4 AND IPv6! aware.<br />IPv6 is not so far as you think.<br />The first step would be to have care of IPv6onIPv4 tunnels and then of the native IPv6 access.<br />Fortunately UFW takes account of IPv6 so be consequent.<br /><br />Regards<br /><br />Andreas Troschka]]></description>
  <pubDate>Thu, 12 Jun 2008 11:22:28 +0000</pubDate>
</item>
        <item>
  <title>Comment from marquinos</title>
  <description><![CDATA[The official web for Gufw :)<br />http://gufw.tuxfamily.org/]]></description>
  <pubDate>Wed, 25 Jun 2008 17:20:52 +0000</pubDate>
</item>
        <item>
  <title>Comment from Thelasko</title>
  <description><![CDATA[If it doesn't have a GUI then it's not "uncomplicated"]]></description>
  <pubDate>Fri, 27 Jun 2008 19:40:28 +0000</pubDate>
</item>
        <item>
  <title>Comment from Vadim P.</title>
  <description><![CDATA[Uncomplicated for server admins, for who ufw was intended ;)<br /><br />gufw is for users]]></description>
  <pubDate>Fri, 27 Jun 2008 20:43:19 +0000</pubDate>
</item>
        <item>
  <title>Comment from Vadim P.</title>
  <description><![CDATA[0.0.7 release is out :)<br /><br />http://gufw.tuxfamily.org/<br /><br />By the way, we're looking for people to help us make a proper .deb, a PPA, and get it into Ubuntu - so if you've been through this process before, please help everybody out!]]></description>
  <pubDate>Fri, 25 Jul 2008 14:29:37 +0000</pubDate>
</item>
        <item>
  <title>Comment from rmn</title>
  <description><![CDATA[there is a great example of gui firewall at:<br /><br />http://www.pardus.org.tr/eng/projects/firewall/index.html]]></description>
  <pubDate>Sat, 30 Aug 2008 08:21:17 +0000</pubDate>
</item>
        <item>
  <title>Comment from marquinos</title>
  <description><![CDATA[0.20.0 release is out :)<br /><br />http://gufw.tuxfamily.org/<br /><br />By the way, we're looking for people to help us make a proper .deb, a PPA, and get it into Ubuntu - so if you've been through this process before, please help everybody out!]]></description>
  <pubDate>Fri, 12 Sep 2008 16:11:42 +0000</pubDate>
</item>
        <item>
  <title>Comment from marquinos</title>
  <description><![CDATA[Thanks to all people by the ideas! :D<br />You can download the last version in:<br />http://gufw.tuxfamily.org/latest-ufw-deb.html<br />Best regards!]]></description>
  <pubDate>Sat, 13 Sep 2008 14:24:28 +0000</pubDate>
</item>
        <item>
  <title>Comment from vprasaj</title>
  <description><![CDATA[Thanx! :)]]></description>
  <pubDate>Fri, 26 Sep 2008 08:06:39 +0000</pubDate>
</item>
        <item>
  <title>Comment from gabim</title>
  <description><![CDATA[Thank you very much! :)]]></description>
  <pubDate>Thu, 02 Oct 2008 07:58:03 +0000</pubDate>
</item>
      </channel>
</rss>
