RE: A simple question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Sudheer,

I like to block all outgoing traffic in case that someone can take control
either from my firewall system or any other system in my network.

The firewall should be the most secure system in your network; however, like
any other system, it is still vulnerable to bugs and exploits.

If the firewall allows everything out, your system can turn out to be the
one used to attack other systems. It might bee too paranoid, but I like to
protect other people from having my systems attacking theirs.

Also, if you don't have a good system security policy, you might not realize
that your system was taken over until the gentleman with the nice black
suits
knock at your door  ....    =)

-- Just my two cents! maybe even less!




> -----Original Message-----
> From: netfilter-admin@xxxxxxxxxxxxxxxxxxx
> [mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx]On Behalf Of Sudheer
> Divakaran
> Sent: Wednesday, August 18, 2004 9:37 PM
> To: Netfilter mailing list
> Subject: A simple question
>
>
> Hi,
>
> In almost all IP Tables articles I've found that the default policy of
> all tables (INPUT,OUTPUT,FORWARD) set to DROP.  I can understand it as
> far as INPUT and FORWARD tables are concerned, but I do not understand
> why should we set the default policy of OUTPUT chain to DROP.  OUTPUT
> chain is responsible for packets originating from the firewall itself.
> Whay should we DROP it?
>
> Thanks,
> Sudheer
>
>
>
> This email message has been scanned for viruses.
>



This email message has been scanned for viruses.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux