Re: jails, ipfilter & stunnel

From: Ng Pheng Siong (ngps_at_netmemetic.com)
Date: 07/16/03

  • Next message: Chris Boyd: "ASMTP setup on 4.8"
    Date: Wed, 16 Jul 2003 09:09:09 +0800
    To: Nicholas Esborn <nick@netdot.net>
    
    

    On Tue, Jul 15, 2003 at 09:19:09AM -0700, Nicholas Esborn wrote:
    > Would it be useful to create multiple IP aliases on lo0, i.e. 127.0.0.2,
    > 127.0.0.3, bind the jails to those, then use ipfw, ipf/ipnat, or a TCP
    > proxy to connect ports on the server's real IP to services bound to the
    > lo0 aliases?

    Yup, I do that on some of my machines. Mostly works. Easy to experiment
    with, too.

    -- 
    Ng Pheng Siong <ngps@netmemetic.com> 
    http://firewall.rulemaker.net  -+- Manage Your Firewall Rulebase Changes
    http://www.post1.com/home/ngps -+- Open Source Python Crypto & SSL
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Chris Boyd: "ASMTP setup on 4.8"

    Relevant Pages

    • RE: IM Programs
      ... want to block these ports. ... you don't need an explicit deny for the other ports. ... Access-list 101 deny any tcp any any eq 5000 ... >Now, when applying these to your firewall, make sure the number ...
      (Security-Basics)
    • Re: What should I block out with my new firewall software?
      ... >> block out that I don't use or need, like UDP or TCP. ... >> activity or attempts from outside hackers to penetrate these ports. ... never stop svchost from comunnicating on the Internet. ... > Web updates, as far as I know, are downloaded the same way that ...
      (comp.security.firewalls)
    • Re: Fingerprinting Windows O/S based on ports open?
      ... finger printing by open default ports is not always ... OS fingerprinting is not as plain and claer cut as it was perhaps a few ... settings in tcp packets. ... >> Looking for a better way to manage your IP security? ...
      (Pen-Test)
    • Re: NFS inconsistent behaviour
      ... of tcp connections in TIME_WAIT state. ... Why there are so many connections in waiting state? ... and remote port so the ports stay in use for a few minutes. ... I ran out of privileged ports due to treemounting on /net from about 50 ...
      (Linux-Kernel)
    • Re: [fw-wiz] Transparent proxies and PMTUD on the (WWW) server side
      ... > a proxy would preserve the lowered MSS while traversing the firewall: ... > Won't each read return as soon as a new TCP frame arrives ... Consider what happens if TWO segments arrive while your proxy ...
      (Firewall-Wizards)