From mboxrd@z Thu Jan 1 00:00:00 1970 From: Antony Stone Subject: Re: How to build a better security setup for my problem? Date: Sat, 13 Mar 2004 17:50:10 +0000 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200403131750.10374.Antony@Soft-Solutions.co.uk> References: <20040313174106.31077.qmail@web41610.mail.yahoo.com> Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: <20040313174106.31077.qmail@web41610.mail.yahoo.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org On Saturday 13 March 2004 5:41 pm, Vlad H. wrote: > Hello to all, > > I have to give internet access to a small group of users from a local > network. Internet interface is eth0 and local lan interface is eth1. I > guess these rules are ok for my intention: > > But I recently found out that mac address can be changed. So, I need a > third security identifier for iptables or any other solution to increase > security. Any clues on this? thx. What is your concern? What activity are you trying to prevent? What activity are you trying to allow (ie: what sort of access to the Internet do you want to allow people - mail? web? ftp? telnet? ssh? etc...) Antony. -- Normal people think "If it ain't broke, don't fix it". Engineers think "If it ain't broke, it doesn't have enough features yet". Please reply to the list; please don't CC me.