From: Stephen Smoogen <smoogen@lanl.gov>
To: Faheem Mitha <faheem@email.unc.edu>
Cc: netfilter@lists.netfilter.org
Subject: Re: comments about lokkit default script
Date: Fri, 12 Sep 2003 13:36:58 -0600 [thread overview]
Message-ID: <1063395418.5967.22.camel@smoogen1.lanl.gov> (raw)
In-Reply-To: <Pine.LNX.4.44.0309121456140.1054-100000@Chrestomanci>
Yes.. sorry I went too fast. If you had multiple computers sitting
behind the computer running iptables then the forward rule is used (EG
something like this:
[Computer 1] <->[switch]->[Netfilter Computer]<->[Earthlink]
[Computer 2] <-----^
In your case the rules below are secure.
[Netfilter computer] <-> [Earthlink]
On Fri, 2003-09-12 at 13:01, Faheem Mitha wrote:
> On Fri, 12 Sep 2003, Stephen Smoogen wrote:
>
> >
> > Basically to understand the script a bit better you should look at how
> > the rules look in the table.
> >
> > iptables -nxvL
> >
> > should give you some output. If the default policies are to ACCEPT
> > things then what is happening is that you are accepting ALL outbound
> > traffic and very little inbound traffic. The newest
> > redhat-config-firewall in their rawhide has some changes to this, but I
> > have been doing custom firewalls for too long now to remember what they
> > are (I think they put in an ESTABLISHED,RELATED rule in now.)
> >
> > Are you forwarding traffic through your firewall or just using it as a
> > client. If you are using it as a client it is pretty ok and secure. If
> > you are using it as a forwarder you will probably want to make some
> > changes for interfaces to be semi-trusted.
>
> I'm not sure what this means. The firewall is set up on my home computer's
> kernel, which is also the only computer I have, no LAN (I think they call
> it). As I understand it, all packets coming and going from my computer
> pass through this firewall. I don't think I am doing any forwarding. Is
> this done for other computers connected to the net through the firewall?
>
> Faheem.
--
Stephen John Smoogen smoogen@lanl.gov
Los Alamos National Labrador CCN-5 Sched 5/40 PH: 4-0645 (note new #)
Ta-03 SM-1498 MailStop B255 DP 10S Los Alamos, NM 87545
-- So shines a good deed in a weary world. = Willy Wonka --
next prev parent reply other threads:[~2003-09-12 19:36 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-09-12 6:11 comments about lokkit default script Faheem Mitha
2003-09-12 8:02 ` Gavin Hamill
2003-09-12 17:26 ` Faheem Mitha
2003-09-12 18:38 ` Stephen Smoogen
2003-09-12 19:01 ` Faheem Mitha
2003-09-12 19:36 ` Stephen Smoogen [this message]
-- strict thread matches above, loose matches on Subject: below --
2003-09-11 15:10 Faheem Mitha
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1063395418.5967.22.camel@smoogen1.lanl.gov \
--to=smoogen@lanl.gov \
--cc=faheem@email.unc.edu \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox