From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ramin Dousti Subject: Re: How to stop imesh with iptables Date: Wed, 11 Jun 2003 20:45:15 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20030612004515.GA7881@cannon.eng.us.uu.net> References: <20030611200517.2278.qmail@web40306.mail.yahoo.com> <02e701c33060$b7439880$1100000a@busbydev> <200306111636.30206.gadgeteer@elegantinnovations.org> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <200306111636.30206.gadgeteer@elegantinnovations.org> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Gadgeteer Cc: netfilter@lists.netfilter.org > > > am I the only person that denies everything by default and > > > only allows the protocols through the firewall that I > > > feel people need to use? > > > > As always: > > Depends on the requirements of the firewall. > > I have yet to see a case made for other than default deny that was not full > of holes ....just like their firewalls 8-) There is no doubt that the default "deny" and just opening the services that are "required" to be accepted is _the_ requirement of any sane firewall. Ramin