Re: [fw-wiz] X server in a Firewall



On Tue, 2006-01-24 at 19:57 -0800, John M wrote:
>
> But what do you think about a _local_ GUI
> administration (via X window) in a firewall?
>
> My question was: what is better (or worse), taking in
> account the GUI requeriment: a local X window server
> running in the firewall, to be managed localy(that is,
> no remote access) or a web server, ssh based system
> or another port based in a proprietary protocol, to be
> managed remotely?
>
> Or rephrasing the question: which is riskier?

Software has bugs.

Having X Windows running on a firewall opens a big risk of local
exploits. What's not installed can not be hacked and does not need to be
maintained.

If you cannot manage the firewall without the local GUI, maybe you
should get another product.

There are enough good products, which do not need a local GUI to
administrate the firewall and do not run on a simple not even hardened
version of Linux or FreeBSD.

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: New?? firewall idea, self-learning?
    ... > If you're bringing up the idea of a self-learning firewall then I don't ... really secure servers don't have any GUI installed. ... drivers and programs can control the input to such drivers and thus ... Command line are good for security, ...
    (comp.security.firewalls)
  • Re: Leopard Firewall Warning
    ... really a problem with the GUI, not the firewall as such. ... alas not UDP or ICMP. ... and connected to an untrusted network. ...
    (uk.comp.sys.mac)
  • Re: Announcement, iptables gui
    ... running a GUI on a firewall is not a pretty good idea (though ... more customers are interested in linux and iptables. ... > operation systems which use a closed source and restrictive license that ...
    (comp.os.linux.security)
  • Re: Announcement, iptables gui
    ... running a GUI on a firewall is not a pretty good idea (though ... more customers are interested in linux and iptables. ... > operation systems which use a closed source and restrictive license that ...
    (comp.os.linux.security)
  • Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
    ... Obscure configuration and implicit rules ... making it hard to understand exactly what firewall does in this and that case ... GUI should be simple and straightforward, ... errors made by the admins thus, indirectly, incresing security and the ...
    (Firewall-Wizards)