Re: small linux firewall/router advice

From: Yan Seiner (yan@oberon.cardinal.lan)
Date: 12/29/01


From: "Yan Seiner" <yan@oberon.cardinal.lan>
Date: Fri, 28 Dec 2001 18:18:54 -0500

It's really a bad idea to depend on security through obscurity.

Your success depends on how much time you spend connected. While your
machine may not be up long enough to do any real damage, getting
compromised is a major pain in the ass - requiring basically a new
install.

I run a wan of several dial-ups that are up 24-7 and each is firewalled,
on each interface. The main server is firewalled on the WAN interfaces as
well as the local network interface.

I find that I get several attempts / day by script kiddies for some kind
of exploit. Why take chances?

Besides which, ipchains/iptables is fun - you learn A LOT about how each
service works. Stretching your mind keeps you young - and that's becoming
more and more important at my age :-)

--Yan

In article <JbXW7.48759$US4.8468158@news2-win.server.ntlworld.com>,
"andrew somerville" <aj.somerville@ntlworld.com> wrote:

> I've also used a standard dial up connection with no firewall for over
> 18 months with no problems i.e. security problems. Andy
>
>



Relevant Pages

  • Re: IIS, homenetwork, teenager, sercurity
    ... Firewall. ... connection is giving you some hardware firewall protection. ... it is a good idea to have any PC that is connected to the internet ... Microsoft plugs their security holes with a patch ...
    (microsoft.public.inetserver.iis.security)
  • Re: Why a firewall for a PC?
    ... > as his ISP so that he can have a broadband connection. ... In the environment I work in, a firewall has a primary purpose ... > computers they can find, looking for open ports, etc. ... or outbound and implement TCP/IP Security on the XP O/S. ...
    (comp.security.firewalls)
  • Re: Need help getting rid of popup called Messenger Service
    ... internet connection it gets back through. ... properly configured firewall. ... And ignoring or just "putting up with" the security gap represented by these messages is particularly foolish. ... Messenger Service of Windows ...
    (microsoft.public.windowsxp.help_and_support)
  • Someone please recommend a distro?
    ... providing a *fake* always on connection to the sinternet through my 2 hour ... someone can recommend a suitable lightweight, security oriented distro. ... It needs to be basically a firewall with a few extras, viz: ...
    (comp.os.linux)
  • Re: tcp window size of 1
    ... AFAIK it should change the window size because it is receiving and processing data which will fill and clear the buffer during the connection. ... firewall in between is also a Centos 4.3 machine. ... After doing some tcpdump's I saw the misbehaving interface on the Centos server. ...
    (comp.os.linux.networking)