From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Mark E. Donaldson" Subject: RE: SUN RPC portmap Date: Sat, 26 Jun 2004 11:51:04 -0700 Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <200406251600.i5PG0vD4005549@ylpvm29.prodigy.net> Reply-To: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200406251600.i5PG0vD4005549@ylpvm29.prodigy.net> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: 'Spiro Azkoul' , netfilter@lists.netfilter.org -----Original Message----- From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Spiro Azkoul Sent: Friday, June 25, 2004 9:01 AM To: netfilter@lists.netfilter.org Subject: SUN RPC portmap Can anyone think of a reason to simple block SUN RPC via iptables rather than simply stopping the service if it is a mail/pop/imap/web server? Thanks It's normally referred to as "Defense-in-Depth". It is not recommended to rely on a single method of security for anything. If the attacker gets through the front line, it's always nice to know there is a second or third or fourth, etc, etc, layer of defense to stop them.