Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Configuration
From: sgcccdc @ citec . qld . gov . au (Colin Campbell)
Date: Wed, 15 Nov 1995 13:58:45 +1000 (EST)
To: peter @ nmti . com (Peter da Silva)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <9511150138 . AA00852 @ sonic . nmti . com . nmti . com> from "Peter da Silva" at Nov 14, 95 07:38:35 pm

My mailer thinks Peter da Silva said:
> 
> Does turning off "deny hosts unknown" really reduce security that much?
> 
> You shouldn't have any rules that depend on DNS, right?
> 
> Right?

They do not depend on DNS - if DNS fails the host shows up as unknown
and they don't get in. Right?

I use IP addresses only in netperm-table. If the reverse lookup fails
either the host attempting access is not in DNS and therefore I do not
want them using the service, or DNS failed and since I can't "verify"
the IP address, access is again denied. Note that the lookups are
performed on an internal DNS (unless someone has changed resolv.conf :-).

I also have one line in netperm-table oer host so having the "unknown"
line is overkill I guess. It does however, in a perverse kind of way
let me know if DNS is playing up - someone who used to be able to get out
now can't -> DNS broken :-)

If you have a wildcard like "permit hosts *" then the "unknown" line
adds security.

Am I talking rubbish?

Colin


Follow-Ups:
References:
Indexed By Date Previous: Re: Configuration
From: peter @ nmti . com (Peter da Silva)
Next: Re: Vendor Product Access
From: bobk @ manzanita . DEV . 3Com . COM (Bob Konigsberg)
Indexed By Thread Previous: Re: Configuration
From: peter @ nmti . com (Peter da Silva)
Next: Re: Configuration
From: peter @ nmti . com (Peter da Silva)

Google
 
Search Internet Search www.greatcircle.com