On Thu, 17 Aug 2000, Thomas-Peter Klug wrote:

> Recently I've registered MiamiDX. Former I was using Miami 2.95, setting
> "Database/IP-Filter" in a way that I thought they will protect me from
> some nasty 'attacks" from same lazy and weird-minded kids in the Net. I
> decided to log everything what happens through UDP/TCP and to deny
> access from non-system ports like 19, 139 or 27354, for example. On the
> one side the system was quite safe from nukes, but on the other side
> very vulnerable from things like ping-flood or every ftp-transfer was
> generating a log. 
> 
> Now, using MiamiDx, I've ping-flood detection, and a firewall-feature.
> Now I need some help for setting up this firewall. Does anyone have some
> close information about it and give same tips how to set it up in a
> proper and USEFUL way ? 

In most cases, just setting it to "automatic" blocks all the "dangerous"
accesses, but you may have to add entries to permit certain types of
access if desired.  The default setup does include an entry to allow ident
requests through.

On 14 Aug 2000, Neil Bothwick wrote:
> Fred Wright said, 
> >> By: Neil Bothwick <[EMAIL PROTECTED]>
> 
> >> >> Am I "safe"? :-)
> >> 
> >> > Not really. Instead of IP filters (which aren't actually filtering
> >> > anything in your case) use the firewall in TCP/IP->LAN-Connect to
> >> > block unwanted accesses.
> 
> > With a single machine, the IP Filter is just as effective if it's set up
> > correctly.
> 
> "if it's set up correctly". The firewall is simpler to set up, although
> not as powerful as you say. IP filters need configuring, whereas you can
> just turn on the firewall.

The only major difference is that the firewall blocks all service ports by
default, while the IP Filter allows them.  Once you add the three IP
Filter entries recommended in Miami(Dx).guide, it's essentially equivalent
to the default automatic firewall setup for a single-machine network.  You
then need to be careful that any entries intended to allow access to
additional service ports are inserted before the "catchall" blocking
entry.

                                        Fred Wright


-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to