also sprach Gareth Bowker <[EMAIL PROTECTED]> [2002.02.07.1017 +0100]:
> If you're worried about missing stuff out, you could start with a firewall
> that defaults everything to DROP and go from there...

good point. any-any-any-DROP is what i call the base firewall. there
is *no* argument for a firewall that's based on anything but this
essential rule. there *should* also be a rule any-any-any-LOG right
before.

-- 
martin;              (greetings from the heart of the sun.)
  \____ echo mailto: !#^."<*>"|tr "<*> mailto:"; [EMAIL PROTECTED]
  
at the turn of the century in vienna,
the schoenberg food factory stopped making tonic,
and started making cereal instead.
                                                   -- hofstadter's geb

Attachment: pgpUq6Wo7mXJZ.pgp
Description: PGP signature

Reply via email to