Re: pf and broadcasts

From: Peter N. M. Hansteen (peter_at_bgnett.no)
Date: 02/02/05

  • Next message: PP: "Re: pf and broadcasts"
    Date: 02 Feb 2005 21:50:05 +0100
    
    

    "PP" <someone@microsoft.com> writes:

    > The $priv_nets macro in the PF example ruleset however does not so I assume
    > _that_ ruleset _would_ be leaking netbios, wouldn't it?
    >
    > http://www.openbsd.org/faq/pf/example1.html#allrules

    That rule set lets machines on the inside start any connection they
    desire to the outside world and receive return traffic (the main use of
    'keep state').

    Hosts on the outside would as far as I can see not be able to contact
    hosts on the inside on any ports other than $tcp_services.

    It looks like the PFUG authors had mainly OpenBSD machines in mind ;)

    With Microsoft machines on the inside, I would tend to allow outgoing
    connections on only a short list of ports.

    -- 
    Peter N. M. Hansteen, member of the first RFC 1149 implementation team
    http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/
    "First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales"
    

  • Next message: PP: "Re: pf and broadcasts"

    Relevant Pages

    • Re: Babysitting on iptables requested :-)
      ... Here's the list of ports that I see probed then I take the "Probe my ... this was a friendly probe; all packets were TCP SYNs - ... SYN is a packet that is used to initiate a TCP connection. ... >> between Windows machines, so without this a Windows machine in your ...
      (comp.os.linux.security)
    • Re: Connecting through Remote Desktop Connection over WAN
      ... I am able to create a VPN connecting using the connection manager, but i cant connect using RDC directly. ... The ports are open in the firewall on both ends. ... two NICs and the machines on the LAN are connected to the router through the SBS. ...
      (microsoft.public.windows.server.sbs)
    • Re: More on caching and logging
      ... Please point to a citation of where, exactly, Apple said any such thing. ... PPC machines are still the majority of Macs, ... By the end of the first year I had that machine, ... single-button, and the connection was still proprietary, but the ADB ...
      (comp.sys.mac.system)
    • Re: Aborted/dead network connections and other oddities
      ... Once this was done operation of the FTP server returned to ... and seemingly locking out machines. ... > or 30) and then the connection will abort. ...
      (comp.os.linux.networking)
    • Re: More Peer 2 Peer Troubles
      ... Only the Host has been connected to the internet, ... all machines, not just the host. ... Have you enabled ICS on the host's Bigpond connection? ...
      (microsoft.public.windowsxp.network_web)