Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Re[2]: NT NAT
From: Ron DuFresne <dufresne @ parka . winternet . com>
Date: Sat, 4 Jan 1997 21:07:59 -0600 (CST)
To: Bernd Eckenfels <lists @ lina . inka . de>
Cc: ckn @ findata . se, firewalls @ GreatCircle . COM
In-reply-to: <m0vggy9-0004ixC @ lina>

And for the 2.0.x kernels there is a patch to help control syn floods...

Later,

Ron DuFresne

On Sun, 5 Jan 1997, Bernd Eckenfels wrote:

> Hello,
> 
> >                                                 Do I need to care about
> > source routed packets if my upstream provider has everything configured
> > as they should?
> 
> Ask your upstream providee, how should we know if he is filtering source
> routed packets? You can drop them at your router which links you to the
> outside world. Use fireeall rules or settings like "drop source routed
> frames"with linux.
> 
> > If I am using for example Linux, would it be enough to
> > configure the linux kernel to drop source routed packets? To configure the
> > linux firewall to ignore localnet packets from the external link?
> 
> Both. And to ignore PAckates from your internal net as the source on
> external interfaces. And ignore packates with internal address as source on
> external interface and so on. This will prevent you from IP-Spoofing and
> will block most simple attacks.
> 
> Greetings
> Bernd
> y
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Cutting the space budget really restores my faith in humanity.  It
eliminates dreams, goals, and ideals and lets us get straight to the
business of hate, debauchery, and self-annihilation." -- Johnny Hart
	***testing, only testing, and damn good at it too!***

OK, so you're a Ph.D.  Just don't touch anything.



References:
Indexed By Date Previous: Re: Re[2]: NT NAT
From: Ron DuFresne <dufresne @ parka . winternet . com>
Next: which mta 4 dmz
From: Paonia Ezrine <paonia @ exon . massart . mass . edu>
Indexed By Thread Previous: Re: Re[2]: NT NAT
From: lists @ lina . inka . de (Bernd Eckenfels)
Next: Re: Re[2]: NT NAT
From: Paul Ferguson <pferguso @ cisco . com>

Google
 
Search Internet Search www.greatcircle.com