|
Firewalls (August 1995) |
On a number of occassions we have wished to support a service listener on only one particular network interface, and to have nothing on all the other interfaces. Remember that even if a service is listening on only one address, packets addressed to it can still arrive on other interfaces. To be sure, an enemy will need to know what that other address is, and may have trouble routing to it -- but the former isn't always hard to learn, and source routing can do the latter.
|