Security Basics mailing list archives

Re: Firewall setup


From: irado furioso com tudo <irado () hotpop com>
Date: Mon, 15 Sep 2003 20:50:01 -0300

On Mon, 15 Sep 2003 16:33:46 +0100 (BST)
Gaz Wilson <dragon () dragons org uk> wrote:

it strikes me that being a bit more proactive
and blocking certain outgoing ports would be a good idea.  I don't
need any MS based traffic leaving the private network, so 

suggest the 'block all' approach: just deny ALL to in/out, only allow
the real needed ones, say:

allow out 20-21,22,25,80,110
block all others

for the IN rules you can build similar ones

a FreeBSD box with statefull rules (either ipfw or ipfilter) will do the
trick.

---------------------------------------------------------------------------
Captus Networks 
Are you prepared for the next Sobig & Blaster? 
 - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
 - Precisely Define and Implement Network Security 
 - Automatically Control P2P, IM and Spam Traffic 
FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
http://www.captusnetworks.com/ads/42.htm
----------------------------------------------------------------------------


Current thread: