Re: [fw-wiz] Do you permit X11 via proxy firewall?



On 9/5/07, ArkanoiD <ark@xxxxxxxxx> wrote:
And, if yes, how do you implement it?
. . .
Or is x11 firewall support just a useless tradition?

If you already permit SSH, then X11 can trivially be tunneled in SSH.
Well, technically, any protocol can run inside SSH (if you have the
latest OpenSSH), but X is particularly well-supported.


On 9/5/07, Skough Axel U/IT-S <axel.skough@xxxxxx> wrote:
Why should one desire the allowance of a computer from unsecure network to control the keyboard and screen on a computer on inside?
I would strongly recommend total blocking of the X11 ports through a firewall regardless of the vendor!

What about the issue of permitting *outbound* connections from
internal hosts to access X11 on the "outside" of the firewall,
including on your DMZ? Perhaps X has been superseded by VNC, RDP, and
Citrix, and is no longer a consideration for firewall policies?

Kevin
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: [fw-wiz] Is NAT in OpenBSD PF UPnP enabled or Non UPnP?
    ... >> I start by not giving logins and SSH access to users I don't trust. ... a network topology which goes around the ... >> firewall and thus is a serious hole to network security. ... >> have access via UPnP to, well, anything that device might happen to ...
    (Firewall-Wizards)
  • Re: Suns mess up with ssh - any solution for me?
    ... > If you're forwarding X11 through ssh, you don't want to do this. ... patch 118305-04, which I installed by the downloading the reccomended ...
    (comp.unix.solaris)
  • Re: Suns mess up with ssh - any solution for me?
    ... > If you're forwarding X11 through ssh, you don't want to do this. ... patch 118305-04, which I installed by the downloading the reccomended ...
    (comp.sys.sun.admin)
  • Re: ssh attempts
    ... the excellent iptables firewall you probably already have on your system. ... consider changing the port SSH listens on. ... Login to account webmaster not allowed or account non-existent. ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • Re: probleme mit ssh
    ... waehrend das entfernte System der Server ist. ... Bei X11 ist alles andersherum, da ist das entfernte System der Client ... und dein lokales Display der Server. ... DArum brauchsts bei SSH ...
    (de.comp.os.unix.networking.misc)