Re: Secure distribution

From: all mail refused (elvis_at_notatla.org.uk)
Date: 09/13/03


Date: 12 Sep 2003 22:03:50 GMT

In article <120920031229498407%shafferj@mac.com>, Justin Shaffer wrote:

>need to make available to the outside world. What type of network will
>the machine be deployed in? Do you have the luxury of a firewall, or
>will you be using iptables or something similar on the machine itself?

Firewalls don't do a lot for webservers as far as web traffic is concerned
at least if you can keep to the ideal of offering only one service to
the public.

I do think they're important for stopping unexpected outbound traffic.

>> I use Mandrake as a desktop system, but wonder if other distributions such as
>> Trustix (www.trustix.net) or Openna (www.openna.com) offer better security
>> for running a server.

Immunix and OpenBSD are my choices. Both of these have some protection for
buggy software - the main flaw in moderately well-configured systems.

-- 
<rosannetuerlk@ifrance.com> http://www.ulikeit.biz/promo.php?id=
<joy_edit@mail.online.sh.cn> is over quota


Relevant Pages

  • Re: Secure distribution
    ... In article, Justin Shaffer wrote: ... Do you have the luxury of a firewall, ... >will you be using iptables or something similar on the machine itself? ...
    (comp.os.linux.security)
  • Re: Feedback solicited - best way to harden a mail/web server?
    ... Was the system protected by a properly configured firewall? ... it's not a bad "starting point" and it can generate an IPtables rule ... > nor is there a web or ftp server; aside from that I haven't tried to secure ... Before I'll install some nifty application ...
    (comp.os.linux.security)
  • Re: EMERGENCY - need to secure my server against an ongoing SPAMMER
    ... computer with a broadband connection. ... that IP range will prevent that spammer from wasting your systems ... This approach eventually makes your firewall machine so busy it has ... A better approach is to use IPTables to deny ALL inbound attempts to ...
    (Fedora)
  • linux - iptable firewall DNS question
    ... When my firewall is active, i am unable to use name solving features from my ... iptables -P INPUT ACCEPT ... # $ipnet -> adresse ip de l'interface connectée à internet ... echo ACCES AU FIREWALL DEPUIS LOCAL ...
    (comp.security.firewalls)
  • Re: firestarter start failure?
    ... It writes to iptables firewall rules, and then is done, ... unless gui is open. ... Do I have to start Firestarter after I have rebooted? ... When Firestarter is installed from a package, the firewall ...
    (Ubuntu)