Re: is this right?

From: Shawn (greyhat@attbi.com)
Date: 05/09/02


From: "Shawn" <greyhat@attbi.com>
Date: Thu, 09 May 2002 00:55:49 GMT


> I run redhat 7.2 on a DSL connection. The DSL modem I use requires the
user
> to open "pinholes" before the service becomes available to the "outside
> world". I have opened the ports that I need, and on those ports (ie: FTP
> :21), I have restricted these ports on my server (ie: FTP restricted to
real
> users only......class real *).

First off, what are you calling pinholes? What kind of DSL modem do you
have? Unless your modem has a built-in firewall or NAT'ing, more than likely
it does NOT block traffic. You should focus on securing your connection from
the server.

> My question is......do I need to configure my server firewall, or does the
> modem block all ports I haven't opened - therfore requiring me to only
> configure the servers security on the modems open ports. Example: I have
> closed port 22 on the modem, so I shouldn't need to attend to sshd
security?

Security through obscurity is NOT a good theory to follow. As a rule of
thumb, you should turn off all the services you don't need on the server;
period! Hope this helps..

--
Shawn
www.intrusiondefense.com



Relevant Pages

  • Re: Liunx and DSL routing
    ... to eth1 on the server. ... confused is the difference between the modem WAN and LAN addresses. ... > others mean just forwarding all the ports. ...
    (comp.os.linux.networking)
  • Re: Upgrade XP Home to Pro and lose COM ports
    ... Pro and then I tried to use the modem ... poking around in Device Manager I find there are no COM ports ... under "other devices" a Network Controller listed. ... Wireless PCMCIA card. ...
    (microsoft.public.windowsxp.general)
  • Re: Home Networking Question: Bridging/IP Forwarding between 2 LAN segments
    ... What kind of switch can I buy and add between the modem and network? ... Connect server 6 to the Westell and configure as necessary to allow VNC. ... Linksys LAN ports. ...
    (microsoft.public.win2000.networking)
  • Modem doesnt work with 4.10-STABLE
    ... actually everything went ok during making the world but my modem ... # CVSup allows you to download the latest CVS ... # the files in your ports tree. ... # do not use the same tags as the main part of the FreeBSD source tree. ...
    (freebsd-stable)
  • Re: [kde] Im feeling paranoid - with good reason.
    ... The new one stealths all ports. ... Open source is very open to this sort of thing ... SpeedTouch 510 modem with Shieldup at grc.com. ...
    (KDE)