Re: IPTables configuration.

2002-12-04 Thread Tore Nilsson
From: "DEFFONTAINES Vincent" <[EMAIL PROTECTED]> To: Sent: Wednesday, December 04, 2002 3:45 PM Subject: RE: IPTables configuration. > The call of PAROLE for TCP DST 80 paquets isnt restrictive enough. > I would call that rule only this way : > replace > 384 19

RE: IPTables configuration.

2002-12-04 Thread DEFFONTAINES Vincent
klist many). > -Original Message- > From: Tore Nilsson [mailto:[EMAIL PROTECTED] > Sent: Wednesday 4 December 2002 15:19 > To: DEFFONTAINES Vincent > Cc: debian-security@lists.debian.org > Subject: Re: IPTables configuration. > > > Hi! > > The machine is a standalo

RE: IPTables configuration.

2002-12-04 Thread DEFFONTAINES Vincent
x27;t modify the way the firewall works. > -Original Message- > From: Tore Nilsson [mailto:[EMAIL PROTECTED] > Sent: Wednesday 4 December 2002 15:13 > To: DEFFONTAINES Vincent > Cc: debian-security@lists.debian.org > Subject: Re: IPTables configuration. > >

Re: IPTables configuration.

2002-12-04 Thread Tore Nilsson
Original Message - From: "DEFFONTAINES Vincent" <[EMAIL PROTECTED]> To: Sent: Wednesday, December 04, 2002 2:45 PM Subject: RE: IPTables configuration. > To correctly audit your configuration, I need an output of > "/sbin/iptables -L -n -v" > The mere "

Re: IPTables configuration.

2002-12-04 Thread Martin Rusko
Hello, maybe stupid question, but what role of this host, with a such iptables configuration it is? It is a host firewalling a network behind, or it is a standalone machine in Internet? Also maybe "-v" commandline option could be helpfull. Just first rule, as we can see here: Chain INPUT (p

RE: IPTables configuration.

2002-12-04 Thread DEFFONTAINES Vincent
To correctly audit your configuration, I need an output of "/sbin/iptables -L -n -v" The mere "/sbin/iptables -L [-n]" is not sufficient to me, cause it won't reveal the per interface filters. Vincent > -Original Message- > From: Tore Nilsson [mailto:[EMAIL PROTECTED] > Sent: Wednesday

Re: IPTables configuration.

2002-12-04 Thread Tore Nilsson
From: "DEFFONTAINES Vincent" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, December 04, 2002 3:45 PM Subject: RE: IPTables configuration. > The call of PAROLE for TCP DST 80 paquets isnt restrictive enough. > I would call that rule only

RE: IPTables configuration.

2002-12-04 Thread DEFFONTAINES Vincent
klist many). > -Original Message- > From: Tore Nilsson [mailto:[EMAIL PROTECTED]] > Sent: Wednesday 4 December 2002 15:19 > To: DEFFONTAINES Vincent > Cc: [EMAIL PROTECTED] > Subject: Re: IPTables configuration. > > > Hi! > > The machine is a standalone web server. I'

RE: IPTables configuration.

2002-12-04 Thread DEFFONTAINES Vincent
x27;t modify the way the firewall works. > -Original Message- > From: Tore Nilsson [mailto:[EMAIL PROTECTED]] > Sent: Wednesday 4 December 2002 15:13 > To: DEFFONTAINES Vincent > Cc: [EMAIL PROTECTED] > Subject: Re: IPTables configuration. > > > Hi! > &

Re: IPTables configuration.

2002-12-04 Thread Tore Nilsson
Original Message - From: "DEFFONTAINES Vincent" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, December 04, 2002 2:45 PM Subject: RE: IPTables configuration. > To correctly audit your configuration, I need an output of > "/sbin/ipta

Re: IPTables configuration.

2002-12-04 Thread Martin Rusko
Hello, maybe stupid question, but what role of this host, with a such iptables configuration it is? It is a host firewalling a network behind, or it is a standalone machine in Internet? Also maybe "-v" commandline option could be helpfull. Just first rule, as we can see here: Chain INPUT (poli

RE: IPTables configuration.

2002-12-04 Thread DEFFONTAINES Vincent
To correctly audit your configuration, I need an output of "/sbin/iptables -L -n -v" The mere "/sbin/iptables -L [-n]" is not sufficient to me, cause it won't reveal the per interface filters. Vincent > -Original Message- > From: Tore Nilsson [mailto:[EMAIL PROTECTED]] > Sent: Wednesda