|
|||||||||||
|
Re: Why not have firewall rules by default?
From: Riku Valli <riku.valli(at)vallit.fi>
Date: Wed Jan 23 2008 - 13:44:33 EST
> For example, if only port 22 is allowed (after they install SSH) and If you restrict all over port 1024 you cannot use your computer :) myhost:34873 otherhost:ssh ESTABLISHED otherhost:22 myhost:34873 ESTABLISHED This is reason why use statefull inspection at perimeter firewall. It's open high port/s related a allowed established connection and keep other high port closed if you compare to old router's access list, only ports < 1024 can filtered. Iptables have statefull capabilties. http://www.checkpoint.com/products/downloads/Stateful_Inspection.pdf If you have rootkit with root permissions it can disable your firewall or connect with normal client software to anywhere. So in host firewall you must restrict outside and inside port/s and this is nightmare maintain at normal user desktop. Compare Windows Antivirus/Firewall softwares and why it ask "This program tries connect to internet, allow or deny". Yes many of Windows firewalls are packet filters ie. all high ports open Normally this kind systems are used only servers when needed really tight security. > A few prompts during the installation would be able to make a suitable I like Debian because it don't tried install for me selinux, firewalls and all bells and whistles. This isn't sometimes remember at some distributions :) I can choose myself which is suitable for me.
Regards, Riku
-- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Wed Jan 23 13:45:25 2008 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:55:24 EDT |
||||||||||
|
|||||||||||