Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #70357 > unrolled thread

Yes, You Need A Firewall On Linux - Here’s Why And Which To Use

Started byLawrence D'Oliveiro <ldo@nz.invalid>
First post2025-08-05 08:14 +0000
Last post2025-08-23 05:43 +0000
Articles 20 on this page of 113 — 24 participants

Back to article view | Back to comp.os.linux.misc


Contents

  Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-05 08:14 +0000
    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-05 11:22 +0200
      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marco Moock <mm@dorfdsl.de> - 2025-08-05 11:34 +0200
    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use jayjwa <jayjwa@atr2.ath.cx.invalid> - 2025-08-05 11:30 -0400
      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-05 19:56 +0100
        Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 01:06 +0000
      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John McCue <jmclnx@gmail.com.invalid> - 2025-08-06 01:32 +0000
        Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 04:20 +0000
          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use c186282 <c186282@nnada.net> - 2025-08-06 01:33 -0400
            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-06 09:31 +0100
              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 08:56 +0000
                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-06 10:35 +0100
                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-06 11:38 +0100
                    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-07 00:06 +0000
                      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-11 11:50 +0100
                        Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-11 22:02 +0000
                          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-12 08:39 +0100
                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-12 10:49 +0200
                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-12 10:54 +0100
                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2025-08-12 18:47 +0000
                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-12 23:36 +0000
                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E. R." <robin_listas@es.invalid> - 2025-08-12 12:08 +0200
                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use rbowman <bowman@montana.com> - 2025-08-12 19:35 +0000
                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-12 23:07 +0000
                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-13 09:47 +0100
                                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-14 00:41 +0000
                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-19 12:35 +0200
                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-19 12:18 +0100
                                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-19 15:16 +0200
                                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:02 +0000
                                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-27 06:56 +0100
                                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-28 00:50 +0000
                                    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-28 09:40 +0100
                                      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-29 00:56 +0000
                                        Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-08-29 08:10 -0700
                                          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-29 19:16 +0100
                                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2025-08-30 16:59 +0300
                                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-30 18:45 +0100
                                                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2025-08-31 21:24 +0300
                                                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-09-01 17:02 +0100
                                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-31 03:25 +0000
                                          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-30 06:34 +0000
                                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-30 08:39 +0100
                                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-30 08:45 +0100
                                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Harold Stevens <wookie@trixie.localdomain> - 2025-08-30 05:37 -0500
                                                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-09-02 09:59 -0700
                                                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Harold Stevens <wookie@aspen.localdomain> - 2025-09-02 12:59 -0500
                                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-30 17:48 +0100
                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:01 +0000
                                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-20 12:52 +0200
                                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:36 +0000
                                    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 11:44 +0200
                                      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-21 11:34 +0100
                                        Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 14:36 +0200
                                          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-21 14:27 +0100
                                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 21:37 +0200
                                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-22 10:33 +0100
                                                Manuals [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:39 +0200
                                          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:12 +0000
                                      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:06 +0000
                                        Documentation [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:26 +0200
                                          Re: Documentation [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:13 +0000
                                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-08-20 07:47 -0700
                                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:37 +0000
                              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-20 19:25 +0000
                                tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 12:04 +0200
                                  Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-23 12:40 +0000
                                    Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-24 00:40 +0200
                                    Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:15 +0000
                                      Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-24 11:22 +0000
                                        Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-24 22:18 +0000
                            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Anssi Saari <anssi.saari@usenet.mail.kapsi.fi> - 2025-08-21 12:40 +0300
                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-06 14:21 +0100
                    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-06 16:24 +0100
              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-06 10:12 +0100
            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Anssi Saari <anssi.saari@usenet.mail.kapsi.fi> - 2025-08-07 11:43 +0300
          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John McCue <jmclnx@gmail.com.invalid> - 2025-08-06 11:55 +0000
        Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 07:40 +0200
          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 06:31 +0000
            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 11:06 +0200
              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-06 14:25 +0100
                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 17:11 +0200
                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 23:59 +0000
                    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-07 08:37 +0200
                      Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-07 06:52 +0000
                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Rich <rich@example.invalid> - 2025-08-18 16:49 +0000
        Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-06 12:46 +0200
          Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 23:56 +0000
            Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-19 12:41 +0200
              Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:07 +0000
                Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-20 09:48 +0100
                  Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-20 11:13 +0100
                    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:40 +0000
                    Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use vallor <vallor@cultnix.org> - 2025-08-21 00:27 +0000
                  ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-20 13:04 +0200
                    Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-20 12:30 +0100
                    Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:44 +0000
                      Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 12:15 +0200
                        Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:18 +0000
                          Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:45 +0200
                            Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-22 19:37 +0100
                              Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 22:32 +0200
                                Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-22 21:56 +0100
                                  Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 00:28 +0000
                                    Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-23 05:51 +0000
                                      Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-23 11:23 +0100
                                        Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:12 +0000
                                          Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] candycanearter07 <candycanearter07@candycanearter07.nomail.afraid> - 2025-08-29 19:40 +0000
                                            Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-30 05:59 +0000
                                          Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-30 06:36 +0000
                                          Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-30 10:36 +0200
                                            Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-31 01:25 +0000
                                Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-23 05:43 +0000

Page 5 of 6 — ← Prev page 1 2 3 4 [5] 6  Next page →


#70480

FromRichard Kettlewell <invalid@invalid.invalid>
Date2025-08-06 14:25 +0100
Message-ID<wwvjz3g8tv0.fsf@LkoBDZeT.terraraq.uk>
In reply to#70452
Marc Haber <mh+usenetspam1118@zugschl.us> writes:
> Lawrence D'Oliveiro <ldo@nz.invalid> wrote:
>>  Marc Haber wrote:
>>> Second, blocking incoming echo requests makes debugging harder and
>>> doesn't give you increased security.
>>
>> When a certain server I had responsibility for was undergoing a
>> security audit for PCI compliance many years ago, I was told, not to
>> turn off ICMP replies, but to turn off timestamps on them.
>>
>> Apparently, knowing the server’s idea of the correct time was seen as
>> a potential security vulnerability.

The justification is more likely to have been attack surface
minimization.

> Those consultants are paid to find things. Hence, they find things. Or
> they make things up. The persons who hire them don't care as long as
> there is a report.

A common approach to security is block or disable everything you don’t
need, and leave only the things you do need enabled.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#70487

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2025-08-06 17:11 +0200
Message-ID<106vrb0$1e3u4$1@news1.tnib.de>
In reply to#70480
Richard Kettlewell <invalid@invalid.invalid> wrote:
>Marc Haber <mh+usenetspam1118@zugschl.us> writes:
>> Those consultants are paid to find things. Hence, they find things. Or
>> they make things up. The persons who hire them don't care as long as
>> there is a report.
>
>A common approach to security is block or disable everything you don’t
>need, and leave only the things you do need enabled.

Then the discussion moves to what is needed. From an operations point
of view, I NEED debugging.

Greetings
Marc
-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#70515

FromLawrence D'Oliveiro <ldo@nz.invalid>
Date2025-08-06 23:59 +0000
Message-ID<1070q96$3m69k$11@dont-email.me>
In reply to#70487
On Wed, 06 Aug 2025 17:11:28 +0200, Marc Haber wrote:

> Richard Kettlewell <invalid@invalid.invalid> wrote:
>>
>>A common approach to security is block or disable everything you don’t
>>need, and leave only the things you do need enabled.
> 
> Then the discussion moves to what is needed. From an operations point of
> view, I NEED debugging.

No reason to make those interfaces public, though.

E.g. for one client, we have the production system on the main VM, even 
though that was originally set up just for me to use for testing.

So when I needed an additional test setup, I created an LXC container 
within the VM, running a separate copy of the software that is not 
actually directly accessible outside the machine. I can only get to it via 
an SSH tunnel.

[toc] | [prev] | [next] | [standalone]


#70527

FromMarc Haber <mh+usenetspam1118@zugschl.us>
Date2025-08-07 08:37 +0200
Message-ID<1071hk6$1id3o$1@news1.tnib.de>
In reply to#70515
Lawrence D'Oliveiro <ldo@nz.invalid> wrote:
>On Wed, 06 Aug 2025 17:11:28 +0200, Marc Haber wrote:
>
>> Richard Kettlewell <invalid@invalid.invalid> wrote:
>>>
>>>A common approach to security is block or disable everything you don’t
>>>need, and leave only the things you do need enabled.
>> 
>> Then the discussion moves to what is needed. From an operations point of
>> view, I NEED debugging.
>
>No reason to make those interfaces public, though.

Yes, that's a different point of view. My different point of view is
not to take security measures that don't increase security but instead
make regular life harder. If a box provides a service to the public,
the public already knows it's there, and IP header analysis can also
be done by accessing the service the machine is there to provide.

Let's agree to disagree here.

-- 
----------------------------------------------------------------------------
Marc Haber         |   " Questions are the         | Mailadresse im Header
Rhein-Neckar, DE   |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402

[toc] | [prev] | [next] | [standalone]


#70530

FromLawrence D'Oliveiro <ldo@nz.invalid>
Date2025-08-07 06:52 +0000
Message-ID<1071ifh$3qrld$1@dont-email.me>
In reply to#70527
On Thu, 07 Aug 2025 08:37:57 +0200, Marc Haber wrote:

> Lawrence D'Oliveiro <ldo@nz.invalid> wrote:
>>
>> On Wed, 06 Aug 2025 17:11:28 +0200, Marc Haber wrote:
>>
>>> Then the discussion moves to what is needed. From an operations point
>>> of view, I NEED debugging.
>>
>> No reason to make those interfaces public, though.
> 
> Yes, that's a different point of view. My different point of view is not
> to take security measures that don't increase security but instead make
> regular life harder. If a box provides a service to the public, the
> public already knows it's there, and IP header analysis can also be done
> by accessing the service the machine is there to provide.
> 
> Let's agree to disagree here.

Too many security holes have been inadvertently left through things like 
diagnostic ports that should have been closed after testing had completed, 
but found their way into the shipping product, back-door “testing” 
accounts with full privileges and hard-coded passwords again that should 
have been removed from the production code but were not, that kind of 
thing.

[toc] | [prev] | [next] | [standalone]


#71581

FromRich <rich@example.invalid>
Date2025-08-18 16:49 +0000
Message-ID<107vlj4$36r35$1@dont-email.me>
In reply to#70480
Richard Kettlewell <invalid@invalid.invalid> wrote:
> Marc Haber <mh+usenetspam1118@zugschl.us> writes:
>> Lawrence D'Oliveiro <ldo@nz.invalid> wrote:
>>>  Marc Haber wrote:
>>>> Second, blocking incoming echo requests makes debugging harder and 
>>>> doesn't give you increased security.
>>>
>>> When a certain server I had responsibility for was undergoing a 
>>> security audit for PCI compliance many years ago, I was told, not 
>>> to turn off ICMP replies, but to turn off timestamps on them.
>>>
>>> Apparently, knowing the server’s idea of the correct time was seen 
>>> as a potential security vulnerability.
> 
> The justification is more likely to have been attack surface 
> minimization.

Another possibility is attempting to cover up for an insecure 
initialization of a random number generator from "the current time".

[toc] | [prev] | [next] | [standalone]


#70463

From"Carlos E.R." <robin_listas@es.invalid>
Date2025-08-06 12:46 +0200
Message-ID<6dobmlx9de.ln2@Telcontar.valinor>
In reply to#70416
On 2025-08-06 03:32, John McCue wrote:
> jayjwa <jayjwa@atr2.ath.cx.invalid> wrote:
>> I say it depends on the situation. For a home user, no. Unless you
>> open something there's nothing listening there to exploit.
> 
> Yes and no :)  If you are on a Laptop and travel, you may
> want a firewall even if all ports are closed.  I think
> at the very least you should restrict your system from
> reacting to pings (see below).  FWIW, I always have a
> iptables firewall active.
> 
> <snip>

I don't trust my router, provided by the ISP. Thus all my computers have 
a firewall up.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#70514

FromLawrence D'Oliveiro <ldo@nz.invalid>
Date2025-08-06 23:56 +0000
Message-ID<1070q3q$3m69k$10@dont-email.me>
In reply to#70463
On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote:

> I don't trust my router, provided by the ISP.

I bought my own. I could even run my own routing stack on a Linux box.

[toc] | [prev] | [next] | [standalone]


#71643

From"Carlos E.R." <robin_listas@es.invalid>
Date2025-08-19 12:41 +0200
Message-ID<a01enlxmr9.ln2@Telcontar.valinor>
In reply to#70514
On 2025-08-07 01:56, Lawrence D'Oliveiro wrote:
> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote:
> 
>> I don't trust my router, provided by the ISP.
> 
> I bought my own. I could even run my own routing stack on a Linux box.

The configuration needed by the ISP on the router is not documented, you 
have to reverse engineer the existing documentation in one of their 
routers. And it is far from simple.

The router handles internet, obviously, but also phone and TV.

And then, when the router (or anything) stops working, you are on your own.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#71699

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2025-08-20 01:07 +0000
Message-ID<1083746$1m96$13@dont-email.me>
In reply to#71643
On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote:

> On 2025-08-07 01:56, Lawrence D'Oliveiro wrote:
>>
>> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote:
>> 
>>> I don't trust my router, provided by the ISP.
>> 
>> I bought my own. I could even run my own routing stack on a Linux box.
> 
> The configuration needed by the ISP on the router is not documented ...

Here in NZ it’s all standard protocols. I bought the router from a local 
retailer, not from the ISP. Setup was straightforward -- the router calls 
the setup option I am using “Dynamic IP”, but I think it’s just DHCP.

[toc] | [prev] | [next] | [standalone]


#71720

FromNuno Silva <nunojsilva@invalid.invalid>
Date2025-08-20 09:48 +0100
Message-ID<108425m$7efa$3@dont-email.me>
In reply to#71699
On 2025-08-20, Lawrence D’Oliveiro wrote:

> On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote:
>
>> On 2025-08-07 01:56, Lawrence D'Oliveiro wrote:
>>>
>>> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote:
>>> 
>>>> I don't trust my router, provided by the ISP.
>>> 
>>> I bought my own. I could even run my own routing stack on a Linux box.
>> 
>> The configuration needed by the ISP on the router is not documented ...
>
> Here in NZ it’s all standard protocols. I bought the router from a local 
> retailer, not from the ISP. Setup was straightforward -- the router calls 
> the setup option I am using “Dynamic IP”, but I think it’s just DHCP.

In this case, I think we're talking about a box with router and a bunch
of other stuff, to deal with incoming GPON (can this part still be
called modem, or the workings of fiber disqualify that?) and at least
outgoing coax for TV, RJ11 for telephony and 8p8c for Ethernet.

I've seen these called "ONT", but it seems (from another thread here)
that this may not be entirely appropriate either?

-- 
Nuno Silva

[toc] | [prev] | [next] | [standalone]


#71740

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2025-08-20 11:13 +0100
Message-ID<108474l$7mtq$17@dont-email.me>
In reply to#71720
On 20/08/2025 09:48, Nuno Silva wrote:
> On 2025-08-20, Lawrence D’Oliveiro wrote:
> 
>> On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote:
>>
>>> On 2025-08-07 01:56, Lawrence D'Oliveiro wrote:
>>>>
>>>> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote:
>>>>
>>>>> I don't trust my router, provided by the ISP.
>>>>
>>>> I bought my own. I could even run my own routing stack on a Linux box.
>>>
>>> The configuration needed by the ISP on the router is not documented ...
>>
>> Here in NZ it’s all standard protocols. I bought the router from a local
>> retailer, not from the ISP. Setup was straightforward -- the router calls
>> the setup option I am using “Dynamic IP”, but I think it’s just DHCP.
> 
> In this case, I think we're talking about a box with router and a bunch
> of other stuff, to deal with incoming GPON (can this part still be
> called modem, or the workings of fiber disqualify that?)

I call it a modem, because it modulates and demodulates from IP over 
Ethernet to GPON over fibre, but I get called out because BT call it 
NTE. Network termination equipment.

Which it only is as far as their legal responsibility goes. NTEs are the 
ethernet chips in my devices,

  te UK currently and with coax its common to have a separate 'modem' 
and 'router'

Wankers


> and at least
> outgoing coax for TV, RJ11 for telephony and 8p8c for Ethernet.
> 
> I've seen these called "ONT", but it seems (from another thread here)
> that this may not be entirely appropriate either?
> 
Optical Network Terminator. That's better than NTE at least

Oh well, its all grist to the ArtStudent™ mill where names and ideas are 
far more important that the reality of what they refer to.

Routers were never juts routers either, they were routers plus switches 
plus modems plus wireless bridges...


-- 
When plunder becomes a way of life for a group of men in a society, over 
the course of time they create for themselves a legal system that 
authorizes it and a moral code that glorifies it.

  Frédéric Bastiat

[toc] | [prev] | [next] | [standalone]


#71799

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2025-08-20 22:40 +0000
Message-ID<1085itr$j3am$13@dont-email.me>
In reply to#71740
On Wed, 20 Aug 2025 11:13:41 +0100, The Natural Philosopher wrote:

> Routers were never juts routers either, they were routers plus switches
> plus modems plus wireless bridges...

My router has no “modem” functionality (unless you count Ethernet as 
requiring a “modem”). It has four Ethernet ports, which can be 
individually configured to be on any of three separate networks, so I’m 
not sure if that counts as “routing” or “switching”.

Its wi-fi functionality is disabled, since that is currently provided by a 
separate Linux box that is bridging the wi-fi with the Ethernet LAN.

[toc] | [prev] | [next] | [standalone]


#71803

Fromvallor <vallor@cultnix.org>
Date2025-08-21 00:27 +0000
Message-ID<mgn7flF8ba2U9@mid.individual.net>
In reply to#71740
On Wed, 20 Aug 2025 11:13:41 +0100, The Natural Philosopher
<tnp@invalid.invalid> wrote in <108474l$7mtq$17@dont-email.me>:

> Optical Network Terminator. That's better than NTE at least
> 
> Oh well, its all grist to the ArtStudent™ mill where names and ideas are
> far more important that the reality of what they refer to.
> 
> Routers were never juts routers either, they were routers plus switches
> plus modems plus wireless bridges...

Here I have an ONT -- which acts as a special bridge -- which
connects via 10GBaseT to the 10G Eero router, which has 10G ports
and wifi.  10G to my 10G switch, which handles my 10G workstation
and 10G Synology NAS.

I need to run a Cat-7 wire straight down to Mrs. vallor's office
downstairs so she'll be wired, but currently, the wifi signal
is strong -- and she hasn't complained.

I tried setting up Link Aggregation with this Netgear switch (my
workstation has 2 - 10GBase-T ports, as does the NAS), but the
switch only handles Static LAG, and it's a bit flakey.  I bought
a switch to replace it that supports LACP, but haven't gotten
the round tuit to move over to it yet.

Oh, and the connection to the ONT is 10G XPON.  We believe
in getting customers to go as fast as possible -- this nonsense
by our competitors to hold down connection speeds so they can
soak the customer for upgrades stinks to high heaven.

Finally, the Eero router does IPv4 NAT, and also acts as
a firewall for IPv6.  Native IPv6 is a lovely thing.

-- 
-v System76 Thelio Mega v1.1 x86_64 NVIDIA RTX 3090Ti 24G
   OS: Linux 6.16.1 D: Mint 22.1 DE: Xfce 4.18 
   NVIDIA: 580.76.05 Mem: 258G
   "Some minds should be cultivated, others plowed under..."

[toc] | [prev] | [next] | [standalone]


#71752 — ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]

From"Carlos E.R." <robin_listas@es.invalid>
Date2025-08-20 13:04 +0200
SubjectISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]
Message-ID<emmgnlxv15.ln2@Telcontar.valinor>
In reply to#71720
On 2025-08-20 10:48, Nuno Silva wrote:
> On 2025-08-20, Lawrence D’Oliveiro wrote:
> 
>> On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote:
>>
>>> On 2025-08-07 01:56, Lawrence D'Oliveiro wrote:
>>>>
>>>> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote:
>>>>
>>>>> I don't trust my router, provided by the ISP.
>>>>
>>>> I bought my own. I could even run my own routing stack on a Linux box.
>>>
>>> The configuration needed by the ISP on the router is not documented ...
>>
>> Here in NZ it’s all standard protocols. I bought the router from a local
>> retailer, not from the ISP. Setup was straightforward -- the router calls
>> the setup option I am using “Dynamic IP”, but I think it’s just DHCP.
> 
> In this case, I think we're talking about a box with router and a bunch
> of other stuff, to deal with incoming GPON (can this part still be
> called modem, or the workings of fiber disqualify that?) and at least
> outgoing coax for TV, RJ11 for telephony and 8p8c for Ethernet.
> 
> I've seen these called "ONT", but it seems (from another thread here)
> that this may not be entirely appropriate either?

Yes, it is GPON. Now the ONT is integrated inside the router. So the 
router has an optical input, has two phone connectors, 4 ethernet 
connectors, and one WiFi access point.

It is all standard protocols, but they have to be configured. The 
optical interface needs some parameters, maybe there is a login and 
password or client number somewhere. The channel in the GPON setup.
The television service needs an VLAN, the VoIp phone service needs 
another... there are a lot of details in the configuration of those many 
standard services that have to be configured. There is not, to my 
knowledge, an ISP provided document listing all that.

There might be in the market routers in which I simply click "Telefónica 
Spain setup" and all is done, but I don't know about them. This did 
exist with ADSL.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#71754 — Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2025-08-20 12:30 +0100
SubjectRe: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]
Message-ID<1084bkf$7mtq$25@dont-email.me>
In reply to#71752
On 20/08/2025 12:04, Carlos E.R. wrote:

> Yes, it is GPON. Now the ONT is integrated inside the router. So the 
> router has an optical input, has two phone connectors, 4 ethernet 
> connectors, and one WiFi access point.
> 
Sadly not Over Here it aint
...

> It is all standard protocols, but they have to be configured. The 
> optical interface needs some parameters, maybe there is a login and 
> password or client number somewhere. The channel in the GPON setup.
> The television service needs an VLAN, the VoIp phone service needs 
> another... there are a lot of details in the configuration of those many 
> standard services that have to be configured. There is not, to my 
> knowledge, an ISP provided document listing all that.
> 
> There might be in the market routers in which I simply click "Telefónica 
> Spain setup" and all is done, but I don't know about them. This did 
> exist with ADSL.
> 
Yes. insofar as parameters are common across all the carriers 
installations, this can be done.

UK ISDN was just different enough from US to make setting up a Cisco 
impossible without the right 'magic spell'.

Well we stumble on in different ways until one turns out to be 'best' or 
at least 'adequate cheap enough and what everyone uses'

It's a real lesson to apply to Darwin.

Never 'survival of the fittest', just elimination of the truly terrible, 
completely bonkers, marginally worse  and just plain unlucky...



-- 
“It is hard to imagine a more stupid decision or more dangerous way of 
making decisions than by putting those decisions in the hands of people 
who pay no price for being wrong.”

Thomas Sowell

[toc] | [prev] | [next] | [standalone]


#71800 — Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2025-08-20 22:44 +0000
SubjectRe: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]
Message-ID<1085j44$j3am$14@dont-email.me>
In reply to#71752
On Wed, 20 Aug 2025 13:04:14 +0200, Carlos E.R. wrote:

> Yes, it is GPON. Now the ONT is integrated inside the router.

Not here in NZ, it isn’t. The demarcation is clear: the ONT is part of the 
house fittings (like curtains or the oven), while the router is a separate 
piece of property. The physical fibre network, up to and including the 
ONT, is managed by a company (Tuatahi Fibre) that is not an ISP and does 
not provide any Internet services.

[toc] | [prev] | [next] | [standalone]


#71838 — Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]

From"Carlos E.R." <robin_listas@es.invalid>
Date2025-08-21 12:15 +0200
SubjectRe: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]
Message-ID<m68jnlxg6h.ln2@Telcontar.valinor>
In reply to#71800
On 2025-08-21 00:44, Lawrence D’Oliveiro wrote:
> On Wed, 20 Aug 2025 13:04:14 +0200, Carlos E.R. wrote:
> 
>> Yes, it is GPON. Now the ONT is integrated inside the router.
> 
> Not here in NZ, it isn’t. The demarcation is clear: the ONT is part of the
> house fittings (like curtains or the oven), while the router is a separate
> piece of property. The physical fibre network, up to and including the
> ONT, is managed by a company (Tuatahi Fibre) that is not an ISP and does
> not provide any Internet services.

When I had an ONT, it was also supplied by the ISP.

The fibre connected to the ONT, and from that it came out an ethernet 
cable to the router, also supplied by the ISP, and the phone cable.

One day they came, removed the ONT and the router, and placed a new 
router. One box less.

Everything belongs to one company, Telefónica. It is possible to 
contract a different company, but the physical fibre is the same one. 
There is also another company that has fibre to the block, then coax to 
the home.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#71892 — Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2025-08-22 01:18 +0000
SubjectRe: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]
Message-ID<1088gh9$19b27$6@dont-email.me>
In reply to#71838
On Thu, 21 Aug 2025 12:15:18 +0200, Carlos E.R. wrote:

> One day they came, removed the ONT and the router, and placed a new
> router. One box less.

And no more possibility of demarcation. Bad.

Another thing that the ONT allows is, I have my landline from a different 
provider from my Internet connection. They come out of different ports on 
the box in my house, though they get here on the same physical piece of 
fibre.

> Everything belongs to one company, Telefónica. It is possible to
> contract a different company, but the physical fibre is the same one.

This sounds like NZ about 30 years ago, after NZ Telecom was privatized, 
and just as the Internet was taking off. Too late, it was realized that 
this left control of the entire NZ phone-number space, as well as 
ownership of the copper lines into every household, in private hands.

The latter problem was solved by the local-loop unbundling I mentioned 
elsewhere -- some described it as a renationalization of the “last-mile” 
copper network in all but name. That made a big difference to the 
competitiveness of the broadband market.

And the mistake was not repeated when the fibre network was put in place.

[toc] | [prev] | [next] | [standalone]


#71913 — Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]

From"Carlos E.R." <robin_listas@es.invalid>
Date2025-08-22 12:45 +0200
SubjectRe: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use]
Message-ID<8bulnlxf5e.ln2@Telcontar.valinor>
In reply to#71892
On 2025-08-22 03:18, Lawrence D’Oliveiro wrote:
> On Thu, 21 Aug 2025 12:15:18 +0200, Carlos E.R. wrote:
> 
>> One day they came, removed the ONT and the router, and placed a new
>> router. One box less.
> 
> And no more possibility of demarcation. Bad.

One good thing, is that we have access to the VoIP configuration and 
install (undocumented) true VoIP phones. We did not have access to 
configure the ONT, and thus, the phone.

I believe people have reverse engineered it all. I was told there is 
some EU directive saying people have the right to install their own routers.

> 
> Another thing that the ONT allows is, I have my landline from a different
> provider from my Internet connection. They come out of different ports on
> the box in my house, though they get here on the same physical piece of
> fibre.
> 
>> Everything belongs to one company, Telefónica. It is possible to
>> contract a different company, but the physical fibre is the same one.
> 
> This sounds like NZ about 30 years ago, after NZ Telecom was privatized,
> and just as the Internet was taking off. Too late, it was realized that
> this left control of the entire NZ phone-number space, as well as
> ownership of the copper lines into every household, in private hands.
> 
> The latter problem was solved by the local-loop unbundling I mentioned
> elsewhere -- some described it as a renationalization of the “last-mile”
> copper network in all but name. That made a big difference to the
> competitiveness of the broadband market.
> 
> And the mistake was not repeated when the fibre network was put in place.

I worked in this field years ago, before fibre. I have not seen the 
fibre exchanges, how they do things.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


Page 5 of 6 — ← Prev page 1 2 3 4 [5] 6  Next page →

Back to top | Article view | comp.os.linux.misc


csiph-web