All of lore.kernel.org
 help / color / mirror / Atom feed
From: Aleksandar Milivojevic <amilivojevic@pbl.ca>
To: netfilter@lists.netfilter.org
Subject: Re: No internet connection
Date: Thu, 09 Sep 2004 12:00:28 -0500	[thread overview]
Message-ID: <41408C2C.6020208@pbl.ca> (raw)
In-Reply-To: <20040909160053.GN8419@metastasis.org.uk>

Nick Drage wrote:
> Not wishing to be paranoid, buuuuuuuuutttttttt..... couldn't you
> usefully restrict those by source and destination IP?

Probably, but...  You usually don't know IP address of DHCP server in 
advance (ISP can chage it without prior notice, which will happen each 
time they deem it is time to reorganize their network).  You don't know 
what will be your address before it is assigned to you.

Theoretically, you could modify dhcpclient so that it opens up firewall 
to be more permissive for those two ports when initially getting IP 
address, and than making it more strict when both local and DHCP 
server's addresses are known (and making it more permissive again if 
DHCP server goes south, so that new one could be discovered).

Theretically, your ISP (I guess it's cable, if using DHCP) should have 
been protecting you anyhow.  Otherwise, any wise ass with Windblows or 
Linux box could screw up entire cable segment.  It would be the last 
thing he would do (since it would be trivial to pinpoint him).  But it 
might be considered as fun last thing by the before mentioned wise ass.

On the other hand, you should also assume ISP is brain dead and have 
everything misconfigured (or in better case, not configured at all ;-)

-- 
Aleksandar Milivojevic <amilivojevic@pbl.ca>    Pollard Banknote Limited
Systems Administrator                           1499 Buffalo Place
Tel: (204) 474-2323 ext 276                     Winnipeg, MB  R3T 1L7


  parent reply	other threads:[~2004-09-09 17:00 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20040909144044.27300.qmail@web50208.mail.yahoo.com>
2004-09-09 15:02 ` No internet connection Jason Opperisano
2004-09-09 16:00   ` Nick Drage
2004-09-09 16:25     ` Jason Opperisano
2004-09-09 17:00     ` Aleksandar Milivojevic [this message]
2004-09-10 14:49 No Internet Connection Giancarlo Boaron
2004-09-10 15:33 ` Jason Opperisano
2004-09-10 16:41 ` Aleksandar Milivojevic
2004-09-10 16:56   ` Jason Opperisano
2004-09-10 17:24     ` Aleksandar Milivojevic
2004-09-10 17:28     ` Giancarlo Boaron
  -- strict thread matches above, loose matches on Subject: below --
2004-09-09 14:06 No internet connection Piszcz, Justin Michael
2004-09-09 14:04 Giancarlo Boaron
2004-09-09 14:15 ` Jason Opperisano
2004-09-09 16:02   ` Nick Drage

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=41408C2C.6020208@pbl.ca \
    --to=amilivojevic@pbl.ca \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.