Re: Computer on network connected to the Internet



On 30 Jun, 04:13, Doug Laidlaw <laidl...@xxxxxxxxxxxxxxxx> wrote:

I cured the problem by creating a special rule enabling SMTP. At least the
graphical wizard saved me the intricacies of whatever takes the place of
iptables. But my basic gripe remains: what is the use of a network if the
computer is firewalled off from it? Why have email capability then stop it
from working? Only lawyers do anything so ridiculous. I was one - and
hated it for that very reason.

Doug - living inside a social firewall, a retirement village, "God's waiting
room."

Many, if not most, Linux systems to nightly cron jobs to rotate logs,
check for updates, scan for weird messages in the system logs, etc.,
etc. These are normally emailed to the cron job owner, who is normally
"root". The SMTP server is used on these systems to deliver the log
messages somewhere useful: the normal restrictive firewall does allow
that server to transfer the email *out* to a remote target, while
refusing all non-local email. On such a system, you may as well block
port 25 incoming, because nothing should be sending to that system
from elsehwere until you're bothered to turn it on.

Does that make more sense?

.



Relevant Pages

  • Re: Strange WAN Activity
    ... > firewall logs for a possible TCP FIN scan that keeps ... > company's intranet server IP and its port 80 across our ... > My firewall is a Sonicwall Pro 200 and I'm running W2K ... It's difficult to be sure without inspecting the web server for signs of ...
    (microsoft.public.win2000.security)
  • Re: Winvnc hack! [25 KB]
    ... came in from a service such as IIS that logs IP address. ... Check your IIS ... Some firewall software such as ... You can also use the NETSTAT -A command that comes with Windows to look at ...
    (microsoft.public.win2000.security)
  • RE: [fw-wiz] Log checking?
    ... tend to evaluate where and what logging is important in a different light. ... I've been happy to analyze a year's worth of firewall denied logs, ... have denied firewall traffic logs or denied logs with any relevant data. ...
    (Firewall-Wizards)
  • Re: really evil ipfw rules
    ... After all of these messages hit your ISP's SMTP server to go out, ... Report the spam to the ISP ... > connection to an SMTP server, there is no connecting ISP. ... Using a firewall DENY rule only works if the spammer is connecting ...
    (comp.security.firewalls)
  • Re: false portscan alarm
    ... What is the reason of that treffic? ... and the browser and/or the "personal firewall" had decided to close those ... which each have a local source port above 1024 opened outgoing to port 80 ... I've had a dig through my own PIX logs, and while there is nothing for today ...
    (comp.security.firewalls)