All of lore.kernel.org
 help / color / mirror / Atom feed
* Implications of a permissive FORWARD chain
@ 2014-02-18 17:53 Mark Fox
  2014-02-18 19:29 ` Leonardo Rodrigues
  2014-02-18 19:57 ` Ambroz Bizjak
  0 siblings, 2 replies; 14+ messages in thread
From: Mark Fox @ 2014-02-18 17:53 UTC (permalink / raw)
  To: netfilter

I've been waffling over a permissive or restrictive FORWARD chain and have
realized that my understanding of the implications is lacking. So I'll just
ask: What are the implications of a permissive FORWARD chain?

My situation is that I am deploying a virtualization/containerization host
at a facility that has one big network for everything (servers, desktop
workstations, etc.). There is no DMZ. As one would expect, the network is
really chatty.

Traffic has to be forwarded to/from the VM/container host to/from the VMs or
containers, so a DROP policy on the FORWARD chain means carefully crafting
rules to allow traffic to be forwarded to the VMs/containers. I have no
issues with that, but it does mean that the future users of the VM/container
host would have to craft their own rules when they add new VMs/containers.


^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2014-02-26 15:42 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-02-18 17:53 Implications of a permissive FORWARD chain Mark Fox
2014-02-18 19:29 ` Leonardo Rodrigues
2014-02-18 20:02   ` Mark Fox
2014-02-18 21:03     ` Amos Jeffries
2014-02-19  1:25       ` Mark Fox
2014-02-18 22:10     ` Neal Murphy
2014-02-19  2:34       ` Mark Fox
2014-02-19  2:52         ` Neal Murphy
2014-02-19 14:38           ` Mark Fox
2014-02-19 18:12             ` Neal Murphy
2014-02-22 23:02             ` Pascal Hambourg
2014-02-26 15:42               ` Mark Fox
2014-02-18 19:57 ` Ambroz Bizjak
2014-02-19  2:38   ` Mark Fox

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.