Re: best firewall option for FreeBSD

From: Bart Matthaei (bart@dreamflow.nl)
Date: 02/27/02


Date: Wed, 27 Feb 2002 12:58:36 +0100
From: Bart Matthaei <bart@dreamflow.nl>
To: Baldur Gislason <baldur@foo.is>


On Wed, Feb 27, 2002 at 11:52:22AM +0000, Baldur Gislason wrote:
> It's never a good idea to silently deny incoming connections on port 113 (RFC1413 ident)
> as remote daemons you connect to often try establishing a connection to your host on that
> port and you won't be served untill they've timed out on the ident connection.

These were just some example firewall rules, not a complete setup.
Also, it's better to reset connections to 113 than to deny them (reset
won't cause a timeout interval, but will just refuse the connection).
But I see no obvious reason why you would want to disable ident. It's
pretty trivial.

Regards,

Bart

-- 
Bart Matthaei                 bart@dreamflow.nl 
Kiss me twice.  I'm schizophrenic.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: identd needed ?
    ... The problem with REJECT is the returned ICMP <port filtered>, ... TCP <connection refused>, so ident waits for timeout anyway. ...
    (comp.os.linux.security)
  • Re: [SLE] PostgreSQL 8 Problem - Please Help
    ... user name and other information about the connection. ... Oidentd is an ident daemon that runs on Linux, ... Oidentd has a flexible mechanism for specifying ... ident responses. ...
    (SuSE)
  • Re: Ident Spoofin
    ... > I'm currently running Redhat 7.2. ... ident doesn't seem to work anymore. ... >connection and replies with the spoofed ident. ... the port seems to be unreachable. ...
    (comp.security.unix)
  • Re: Ident Spoofin
    ... > I'm currently running Redhat 7.2. ... ident doesn't seem to work anymore. ... >connection and replies with the spoofed ident. ... the port seems to be unreachable. ...
    (comp.security.unix)
  • Re: Turn off Ident request on Sendmail Sessions
    ... >Can anyone provide a link or other instructions on how to configure Sendmail ... >Currently, anytime a machine attempts to connect to port 25, Sendmail hangs ... >up until it attempts to do an Ident by connecting back to the originating ... >port 113 stealthed (just drops the packets, not refusing a connection), I've ...
    (comp.mail.sendmail)