Re: firewall without loopback interface



On 19 Jan 2006, in the Usenet newsgroup comp.security.firewalls, in article
<1137723535.970672.53980@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>, saltlick wrote:

>A few years back my college lecturer suggested that the most secure way
>to setup a (linux) firewall is to not have any loopback (lo) interface
>and hence it cannot run any local services but only forward traffic back
>and forth, etc.

Someone has a severe concept/nomenclature problem. The presence or absence
of a loopback interface has nothing to do with the services that are being
offered. The loopback is how the computer talks to _itself_ and if the
loopback is vulnerable, it's because someone already 0wnZ the computer.

What is probably being talked about is not offering any services, OR
limiting access to such services to specific internal hosts. Another
concept is that there is no access FROM the firewall to any other
system inside OR out - that is, the firewall is not considered a trusted
system.

>Obviously you would then have to manage the host from the console.

Gee, my home firewall is an old laptop that doesn't have a case, keyboard
or display and offers no network services. Wonder why that works.

>Any comments ?

http://www.oreilly.com and search for "Practical Unix & Internet
Firewalls" by Zwicky, et.al.

Old guy
.



Relevant Pages

  • firewall without loopback interface
    ... to setup a (linux) ... firewall is to not have any loopback interface and hence it cannot ...
    (comp.security.firewalls)
  • Editing Windows firewall ruleset for 2003 Std ?
    ... sent out via the main interface on 172.31.1.2. ... This works perfectly until I turn on the windows firewall. ... configured both the loopback and external interface to accept ... sending them out through the external interface. ...
    (microsoft.public.windows.server.networking)
  • Re: Windows XP SP2
    ... it doesn't use loopback after all. ... SP2 could be blocking it regardless of your firewall settings. ... I went ahead and installed the patch. ... adverse effects so I felt it was ok. ...
    (comp.security.firewalls)
  • Re: Windows XP SP2
    ... it doesn't use loopback after all. ... SP2 could be blocking it regardless of your firewall settings. ... ZA Pro doesn't show any open ports anytime. ...
    (comp.security.firewalls)
  • Re: iptables: cannot talk to localhost
    ... Any how this is not a good way to allow loopback traffic. ... allowing packets from any interface to use a spoofed localhost source ... address to pass your firewall. ... In other words specify the adapter in which you are allowing it. ...
    (comp.security.firewalls)