|
|||||||||||
|
Re: Why not have firewall rules by default?
From: Riku Valli <riku.valli(at)vallit.fi>
Date: Wed Jan 23 2008 - 11:48:33 EST
Cannot find original and seems at this info is removed from ..doc/iptables. Debian haven't any open services by default, except portmapper and behind portmapper aren't any services. So no need for host firewall. If all services are allowed from host to anywhere firewall cannot do nothing in case when host it compromised and is very difficult made default rules for that. If user install example apache we need mechanism which automatically allow connection/s from outside to service/s. What is different? Host without firewall and port 80 open or host with firewall and rule which open port 80? Regards, Riku -- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Wed Jan 23 12:00:01 2008 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:55:22 EDT |
||||||||||
|
|||||||||||