RE: ruleset

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi

It kewl, Im just greatfull that someone is prepared to look at my ruleset.
I basically need and want to be at secure as I possibly can. Give that my
management is so tight with the funding.
And I appreciate you concern.

Kind Regards and thanks again
Brent Clark


-----Original Message-----
From: netfilter-admin@xxxxxxxxxxxxxxxxxxx
[mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx]On Behalf Of Antony Stone
Sent: Tuesday, July 20, 2004 6:14 PM
To: iptables
Subject: Re: ruleset


On Tuesday 20 July 2004 5:02 pm, Brent Clark wrote:

> Hi all and Antony
>
> Thanks for replying.
> In terms of "I know know nothing about security",

Sorry - I didn't mean it to sound like that - I was trying to say that your
ruleset suggested you were running services on the firewall; running
services
on the firewall is not good security practice; therefore I simply wondered
whether you knew about this maxim.

> unfortunately I have a
> budget and expenditure to worry about, therefore, I cant really afford to
> spend to much on machine etc. Therefore I am forced to run a few services
> on the FW.

No problem - just so long as you're aware of the risks :)

Regards,

Antony.

--
Never automate fully anything that does not have a manual override
capability.
Never design anything that cannot work under degraded conditions in
emergency.

                                                     Please reply to the
list;
                                                           please don't CC
me.





[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux