Re: Controlling ports used by natd

From: Jacques A. Vidrine (nectar_at_FreeBSD.org)
Date: 12/13/03

  • Next message: Eric Masson: "FreeBSD, ipnat & timeouts while loading page"
    Date: Fri, 12 Dec 2003 21:36:42 -0600
    To: Brett Glass <brett@lariat.org>
    
    

    On Fri, Dec 12, 2003 at 04:20:04PM -0700, Brett Glass wrote:
    > It'd be nice to restrict which ports the OS
    > allowed apps to use, not only so that they don't get blocked by a firewall
    > but so that a worm that's gotten into the system is detected. (You could set
    > off an alarm if it tried to bind a "forbidden" port.)

    Er, that's the purpose of PortSentry, I believe, which I mentioned
    earlier :-)

    -- 
    Jacques Vidrine   NTT/Verio SME      FreeBSD UNIX       Heimdal
    nectar@celabo.org jvidrine@verio.net nectar@freebsd.org nectar@kth.se
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Eric Masson: "FreeBSD, ipnat & timeouts while loading page"

    Relevant Pages

    • Re: black ice usage question
      ... > to restrict the entire machine from accessing certain ports either. ... > good firewall will allow the user to restrict all access to only the ... > when it comes to outbound protection. ...
      (comp.security.firewalls)
    • Re: Intermittent Oracle client errors
      ... >ipfilter on my linux boxes, blocking almost all ports beneath 1024 ... things happening with FIN_WAITS - some apps don't clean up correctly, ... going through the firewall, especially if you have people messing ...
      (comp.databases.oracle.server)
    • Should a firewall ONLY allow access to an IP range - as well as blocking ports?
      ... >We do have a firewall but it is set up to let all IPs access the open ... >ports - we can and know how to restrict this to only allowed IPs but ... >access on ports we use to administer the server to an IP range only? ... developed a firewall ruleset to block access to those. ...
      (comp.security.misc)
    • Should a firewall ONLY allow access to an IP range - as well as blocking ports?
      ... >We do have a firewall but it is set up to let all IPs access the open ... >ports - we can and know how to restrict this to only allowed IPs but ... >access on ports we use to administer the server to an IP range only? ... developed a firewall ruleset to block access to those. ...
      (comp.security.firewalls)
    • Should a firewall ONLY allow access to an IP range - as well as blocking ports?
      ... >We do have a firewall but it is set up to let all IPs access the open ... >ports - we can and know how to restrict this to only allowed IPs but ... >access on ports we use to administer the server to an IP range only? ... developed a firewall ruleset to block access to those. ...
      (alt.computer.security)