/Quote
But what I think Linux is missing is a fw that controls outgoing traffic by application (like Zonealarm in windows).
/Quote
you can do this, by cmd name, by uid, by gid, by pid, and by sid. its in the man page. try "man iptables" then hit "/" and type "owner" and hit enter. I just reloaded and in the man file i got this at the end of the section, "NOTE: pid, sid and command matching are broken on SMP" So your mileage may vary.
/Quote
but I was wondering if it was worth having if my network is running through a LinkSys router. Doesn’t the router have a built in firewall?
/Quote
Yes, you cant make a firewall at the router that can block all types of attacks. So you have to fine tune at the desktops. Now you could put something like snort at the router or behind it, goodluck getting that on your Linksys though. Which could reduce the need for desktop firewalls but with tools like firestarter and others the risk doesn't justify the gains. »