TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TCLUG:16582] Firewalls revisited...
On Mon, 24 Apr 2000, Nate Carlson wrote:
> Only problem with setting default policy of DENY is you don't get logging
> when packets are denied...
NO! its good to do both.
What if you somehow have a chain that you can sneak through that gets by
the default-deny?  I could write up a plausable situation.
Just remember to send it off to an LDROP chain when wanted.
You dont really want to log *everything* that drops, do you?  CIFS
broadcasts are annoying as hell to watch.
-- 
Scott Dier <dieman@ringworld.org> #nicnac@efnet 612.301.0265
http://www.ringworld.org/  finger:dieman@destiny.ringworld.org
Wait. Watch. Wonder.
	-J