Re: allow ports above 1024

From: Jem Berkes (jb@users.pc9.org)
Date: 02/05/03


From: Jem Berkes <jb@users.pc9.org>
Date: Wed, 05 Feb 2003 02:57:38 GMT


> Why not use the stateful capabilities of netfilter (iptables) to allow
> the return packets ("--state=established,related").

Ditto on that. This is a tremendous advancement with the 2.4 kernel. You
can essentially tell the network stack to only allow packets that belong to
a legitimate, currently established network connection. So random probes
from attackers see nothing at all open your system, while packets that are
needed for an active connection (e.g. ftp, http, whatever) flow through
without problems.

-- 
Jem Berkes
http://www.pc-tools.net/
Windows, Linux & UNIX software


Relevant Pages

  • Re: allow ports above 1024
    ... This is a tremendous advancement with the 2.4 kernel. ... can essentially tell the network stack to only allow packets that belong to ... a legitimate, currently established network connection. ...
    (comp.security.firewalls)
  • Re: One firewire source to four simultaneous outputs?
    ... Firewire supports both peer to peer and TCP/IP transfers. ... What you can't do is do both over the same network connection. ... received 3,456,884 packets in past 32 mins ...
    (uk.rec.video.digital)
  • Re: Network Connection Drops Under Server 2008
    ... Check with "ping -l 1024 ipaddress/servername -t" for a longer period, maybe its different with larger packets. ... seems to work properly except for the network connection. ... Possible reasons are the Computer Hardware or the ...
    (microsoft.public.windows.server.networking)
  • Re: 2.6.12 Performance problems
    ... >> absolute priority to the network stack I'll ... as dropped packets are not ... How do I tune the "its ok to drop ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: Welcome to Hell / Mysterious networking troubles on FreeBSD
    ... If someone wants to flood your network connection with packets there is ... that all depends on the impact the flood has on your network connection and what kind of contract you have with your upstream provider. ... When there's only one, or a limited set of attacking IP addresses, it's probably easiest to just block traffic from that addresses in the first rule of a firewall. ... Even when lots of hosts are attacking, firewalling them may be beneficial. ...
    (freebsd-hackers)

Quantcast