[ILUG] speaking of port sentry...

kevin lyda kevin at suberic.net
Fri Jul 28 15:42:35 IST 2000


i was bored last night and installed it.  my "firewall" at home
usually has the following running:

mysql - listening on 0.0.0.0:3306
nfs - /home,/u1,/u2 exported *(rw), and /mnt/cdrom *(ro)
lp, tftp, rlogin, sendmail, rwalld, etc...

I'M A LAZY BASTARD OK?!

this has been true for over a year and i'm dialed in a fair bit.
sometimes i download security updates.

so now portsentry is installed.  /etc/exports limits to 192.168.5.0/24
what else?  is there a quick ipchains rule to close out anything except
ssh connecting on ppp0?  (ok ephemeral ports, and a port for gnutella
- 6346)

kevin
-- 
kevin at suberic.net       nothing witty here.
fork()'ed on 37058400
meatspace place: work   




More information about the ILUG mailing list