Jean-Christophe Touvet wrote:
> SunOS/FW1 hint: compile your kernel with IP forwarding disabled (-1). Add an
> adb command (W1) at the end of fwstart script to enable IP forwarding only
> when fw module is loaded, and add the reverse adb command (W0) at the
> beginning of fwstop script. You might also wrap your shutdown command.
>
> -JCT-
I am probably too paranoid: wait FW-1 to start before setting up the
external interface. Why external guys would be able to send packets
on my firewall before the FW-1 module is loaded&started ?
Jean-Francois
--
_____ Jean-Francois Zwobada (mailto:zwobada @
apogee-com .
fr) _______
Apogee Communications Tel : +33 (1) 69 85 56 47
Fax : +33 (1) 69 85 56 48
" ### Retrieving "Murphy's Law" record in database ###
perror: Unknown error code. Refer to the Unlucky User's Guide"
__________________________________________________________________
References:
|
|