From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Brent Clark" Subject: RE: ruleset Date: Tue, 20 Jul 2004 18:31:14 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <200407201713.42696.Antony@Soft-Solutions.co.uk> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200407201713.42696.Antony@Soft-Solutions.co.uk> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: iptables Hi It kewl, Im just greatfull that someone is prepared to look at my ruleset. I basically need and want to be at secure as I possibly can. Give that my management is so tight with the funding. And I appreciate you concern. Kind Regards and thanks again Brent Clark -----Original Message----- From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of Antony Stone Sent: Tuesday, July 20, 2004 6:14 PM To: iptables Subject: Re: ruleset On Tuesday 20 July 2004 5:02 pm, Brent Clark wrote: > Hi all and Antony > > Thanks for replying. > In terms of "I know know nothing about security", Sorry - I didn't mean it to sound like that - I was trying to say that your ruleset suggested you were running services on the firewall; running services on the firewall is not good security practice; therefore I simply wondered whether you knew about this maxim. > unfortunately I have a > budget and expenditure to worry about, therefore, I cant really afford to > spend to much on machine etc. Therefore I am forced to run a few services > on the FW. No problem - just so long as you're aware of the risks :) Regards, Antony. -- Never automate fully anything that does not have a manual override capability. Never design anything that cannot work under degraded conditions in emergency. Please reply to the list; please don't CC me.