At 03:12 PM 4/3/00 +1000, John Clarke wrote:
>1. Default policy is to deny all packets. Then rules are added to allow
> certain packets through the firewall. Note that we use DENY rather
> than REJECT so that the originator doesn't know that their packets are
> being discarded until they time out.
I'll dispute this advice. If i were going to write a serious scanner I'd
take a dropped packet on a known port as sign of firewalling. If i get
rejects from everything but 21 and 80 I'm going to start thinking something
is up. In this situation we're not just trying to block access to servers,
we're trying to hide even their existence. The more you make it look like
a windows box, the better. If they run fingerprinting against the machine
they'll still pick it up as linux, but the more luserfied it seems, the
less likely they're going to suspect that something's up. You could set a
default DENY policy, but they may take that to mean that you're trying to
stop them scanning :)
>2. Allow all packets on the loopback interface and any local ethernets.
>3. Allow any packet in from ppp0 with the ACK bit set.
Doesn't Optus@Home rely on you using ethernet to connect to the cable modem?
Alexander Else
http://cyberchrist.org
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text