Great Circle Associates Firewalls
(March 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Linux firewall question.
From: Bret McDanel <bret @ rehost . com>
Date: Mon, 9 Mar 1998 13:06:35 -0500
To: speed @ barney . iamerica . net
Cc: firewalls @ greatcircle . com
In-reply-to: <Pine . LNX . 3 . 95 . 980305103222 . 1682E-100000 @ barney . iamerica . net>
Reply-to: bret @ rehost . com

I am not sure, but I think one of the big reasons that some people say to
stay away from loadable modules is that assuming someone breaks into your
system, they could reconfigure the modules, and add new ones or replace
existing ones without having to take the system down and rebuild the whole
kernel...

---Reply on mail from Henry Hollenberg about Linux firewall question.
>
> A debate has arisen regarding using loadable modules for a linux based
> firewall system and I'm trying to sort thru the issues involved.
>
> I thought I had read somewhere perhaps here that if at all possible
> loadable modules should be avoided on a firewall system....ie everything
> needed by the kernel and only what is needed should be compiled in.
>
> But now I've run into strong opinion that the kernel should use loadable
> modules.
>
> Am I off base to insist on _not_ using loadable modules.
>
> I'd be intrested in any experience anyone could share.
>
---End reply
--
Bret McDanel                                    http://www.rehost.com
Realistic Technologies, Inc.                             973-514-1144

     These opinions are mine, and may not be the same as my employer




Follow-Ups:
References:
Indexed By Date Previous: Re: Connecting to Ibm AS/400 from outside a fw
From: "Ryan Russell" <ryanr @ sybase . com>
Next: Re: Pentagon Hackers Caught!
From: Don Martin <grey @ usa . net>
Indexed By Thread Previous: Re: Linux firewall question.
From: Alexander Kjeldaas <astor @ guardian . no>
Next: Re: Linux firewall question.
From: Dave Wreski <dave @ nic . com>

Google
 
Search Internet Search www.greatcircle.com