看板FB_security
标 题ipfw question
发信站NCTU CSIE FreeBSD Server (Fri Mar 5 02:29:03 2004)
转信站ptt!FreeBSD.csie.NCTU!not-for-mail
Hello folks.. I have a quick question ipfw in a 4.8 server..
In /etc/rc.conf, if you set this - firewall_type="OPEN", is it also
necessary for this options IPFIREWALL_DEFAULT_TO_ACCEPT in the kernel config
file?
I would think that using the first would be better because it can be
removed, thus allowing no one access, including yourself if you aren't
careful. Whereas the second method above, in the kernel config leaves it
open if no rules exist or if all rules are flushed. So the the big question
is, do I use both, one or the other? I know I can just do options
IPFIREWALL, but I want to ensure no way of locking myself out at initial
reboot, since this is a remote server. I am also aware of the risks of doing
it remotely. But I need to do this.
Thanks for your help.
David Edwards
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (
http://www.grisoft.com).
Version: 6.0.576 / Virus Database: 365 - Release Date: 1/30/2004
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"