Re: iptables & tcp wrappers

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 10/04/04

  • Next message: Ansgar -59cobalt- Wiechers: "Re: iptables & tcp wrappers"
    Date: Mon, 4 Oct 2004 00:01:13 +0200
    To: focus-linux@securityfocus.com
    
    

    On 2004-09-29 harry wrote:
    > Whelan, Paul wrote:
    > > "iptables -L --line-numbers" will show you the line numbers of the
    > > rules.
    > > "iptables -A INPUT -p tcp -s ! ONLY_IP_YOU_WANT --dport 22 -j DROP" will
    > > block every connection to port 22 except ONLY_IP_YOU_WANT.
    >
    > not really... a good firewall (IMHO) drops everything, rejects auth
    > (nasty timeouts on ftp, irc, ... if you just drop auth), and accepts
    > these 4(or 5) icmp requests:
    > "source-quench"
    > "parameter-problem"
    > "time-exceeded"
    > "destination-unreachable"
    > and your clients probably want the "echo-request" too :)

    Add "fragmentation-needed" and "echo-reply".

    Regards
    Ansgar Wiechers

    -- 
    "Those who would give up liberty for a little temporary safety
    deserve neither liberty nor safety, and will lose both."
    --Benjamin Franklin
    

  • Next message: Ansgar -59cobalt- Wiechers: "Re: iptables & tcp wrappers"

    Relevant Pages

    • Re: With all the current BS
      ... They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. ... Those who would give up Essential Liberty to purchase a little Temporary Safety, deserve neither Liberty nor Safety. ...
      (misc.news.internet.discuss)
    • Re: Film review
      ... Hmm, forecast still says 29 tomorrow, but definite ... my legs will fire for a D grade debut tomorrow. ... Temporary Safety, deserve neither Liberty nor Safety. ...
      (alt.sysadmin.recovery)
    • Re: OT:R.I.P
      ... HIs name Is Robert Mcclintock SR. ... Take care of yourself, you deserve it. ... "They that can give up essential liberty to obtain a little temporary safety ...
      (talk.origins)
    • Re: Windows 98 box is owned
      ... I would say a live analysis should be sufficent in your case. ... Running strings against the files may give some additional pointers. ... "Those who would give up liberty for a little temporary safety ...
      (Security-Basics)
    • Fwd: Re: [SLE] DHCP problems using cable modem
      ... Dylan, ... servers and search list via DHCP." ... > temporary safety, deserve neither liberty nor ... temporary safety, ...
      (SuSE)