Jason Hirsch wrote:
> Security is a concern, but so is not allowing freeloaders to spam anyone
> from my system.
> 
> Soo- suggestions on which to implement?

First, if you're using kernel 2.2.x, then there's no reason for you to
patch your kernel.  That functionality has been added to the kernel
proper, and is probably active in your setup now.  The tool that
controls this is ipmasqadm, and an RPM was included in your Red Hat
distribution  :)

I'm not sure what you mean about freeloaders spamming from your system. 
AFAIK, using kernel based port forwarding, you can still use all of your
host based security mechanisms, as well as the user based ones, so
security shouldn't be compromised by this setup.  As long as no one
breaks into the machines behind your masquerade, and sets up a TCP
tunnel, they shouldn't be able to use your machine as a mail relay.


MSG


-- 
To unsubscribe: mail [EMAIL PROTECTED] with "unsubscribe"
as the Subject.

Reply via email to