Linux Netfilter discussions
 help / color / mirror / Atom feed
* why must linux for halted firewall?
@ 2003-09-15  3:16 Chua Boon Ping
  2003-09-16 17:46 ` Jim Carter
  2003-09-16 19:33 ` Nox
  0 siblings, 2 replies; 12+ messages in thread
From: Chua Boon Ping @ 2003-09-15  3:16 UTC (permalink / raw)
  To: netfilter

dear all,
   I am newbie in open source and recently i am busy on some assignment 
concerning "why opts for Linux(netfilter/iptables) rather than OpenBSD to 
implement a Halted Firewall". actually, can OpenBSD be halted just like 
Linux kernel do? As i mentioned, i am newbie and would like have some 
guidance from you guys. Thanks.

Chua

_________________________________________________________________
Using a handphone prepaid card? Reload your credit online! 
http://www.msn.com.my/reloadredir/default.asp



^ permalink raw reply	[flat|nested] 12+ messages in thread
* RE: why must linux for halted firewall?
@ 2003-09-16 19:16 Daniel Chemko
  2003-09-16 20:12 ` Jeffrey Laramie
  0 siblings, 1 reply; 12+ messages in thread
From: Daniel Chemko @ 2003-09-16 19:16 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 1092 bytes --]

 

The ideal of a halted firewall is that the only possible exploit that
could compromise a box is the kernel and the network core itself, and
not depend on having userspace programs to cause possible security
concerns.
 
As for the concern that you can't log, I believe you can send syslogs to
another machine from the kernel, no?
 
I personally don't really care for halted firewalls myself. I constantly
tweak the firewall to my environment (basically daily) so a halted
firewall wouldn't make any sense to me. If you have an ultra static
firewall configuration and physical access to the machine, I can see
that there can be benefit of having it, but you would also need a
read-only storage medium since if the kernel is compromised, they could
still dump garbage to physical disks.
 
 
  


>What would be the benefit in configuring a system like this? It seems
to run contrary to the evolution of IT appliances where you can
configure and manage >everything usually without restarting (firewalls,
switches, print servers, even ups units). I don't get it ;-)


[-- Attachment #2: Type: text/html, Size: 3727 bytes --]

^ permalink raw reply	[flat|nested] 12+ messages in thread
* Re: why must linux for halted firewall?
@ 2003-09-16 19:43 Chua Boon Ping
  2003-09-16 21:58 ` Nox
  0 siblings, 1 reply; 12+ messages in thread
From: Chua Boon Ping @ 2003-09-16 19:43 UTC (permalink / raw)
  To: pheusion; +Cc: netfilter

well... i am currently doing a research paper on Halted Firewall on Linux 
platform. I would like to know can OpenBSD implement such a firewall? can 
OpenBSD halted just like Linux kernel does?

i had read the article. thanks.


>From: Nox <pheusion@snet.net>
>To: Chua Boon Ping <nitb@hotmail.com>
>CC: netfilter@lists.netfilter.org
>Subject: Re: why must linux for halted firewall?
>Date: Tue, 16 Sep 2003 15:33:36 -0400
>
>For us,
>We have a runlevel 0 firewall, from Debian
>it was developed in house, fine tuned by this article:
>
>http://www.samag.com/documents/s=1824/sam0201d/0201d.htm
>
>For us, this FW protects a Bioinformatics cluster,
>which rarely changes on the rules side of things,
>the benefit form our standpoint is the non-access into the machine,
>(No user priv escalation due to no logon)
>the drawback is we currently have no logging enabled.
>(We are working on it.
>
>Hope that helps
>
>Nox
>GenMicro systems
>Bioinformatics applications and devices
>(Website in development)
>
>On Sun, 2003-09-14 at 23:16, Chua Boon Ping wrote:
> > dear all,
> >    I am newbie in open source and recently i am busy on some assignment
> > concerning "why opts for Linux(netfilter/iptables) rather than OpenBSD 
>to
> > implement a Halted Firewall". actually, can OpenBSD be halted just like
> > Linux kernel do? As i mentioned, i am newbie and would like have some
> > guidance from you guys. Thanks.
> >
> > Chua
> >
> > _________________________________________________________________
> > Using a handphone prepaid card? Reload your credit online!
> > http://www.msn.com.my/reloadredir/default.asp
> >
> >
>

_________________________________________________________________
Are you in love? Find a date on MSN Personals http://match.msn.com.my/



^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2003-09-16 21:58 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-09-15  3:16 why must linux for halted firewall? Chua Boon Ping
2003-09-16 17:46 ` Jim Carter
2003-09-16 18:26   ` Cedric Blancher
2003-09-16 18:55     ` Jeffrey Laramie
2003-09-16 19:07       ` Re[2]: " Peteris Krumins
2003-09-16 19:11       ` Cedric Blancher
2003-09-16 19:33 ` Nox
2003-09-16 20:15   ` Cedric Blancher
  -- strict thread matches above, loose matches on Subject: below --
2003-09-16 19:16 Daniel Chemko
2003-09-16 20:12 ` Jeffrey Laramie
2003-09-16 19:43 Chua Boon Ping
2003-09-16 21:58 ` Nox

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox